Privacy Policy
Information on the processing of your personal data pursuant to Art. 13 GDPR
This is an English courtesy translation. The legally binding version is the German Datenschutzerklärung.
Last updated: May 2026
The protection of your personal data is important to us. We process your data exclusively on the basis of statutory provisions (GDPR, German Federal Data Protection Act/BDSG, German Telecommunications-Telemedia Data Protection Act/TTDSG, as well as the North Rhine-Westphalia Healthcare Professions Act and § 203 of the German Criminal Code for medical data). This privacy policy informs you about the key aspects of data processing on our website.
1. Controller
The controller for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
Sara Tijani – Praxis für Podologie
Owner: Sara Tijani
Endenicher Straße 323
53121 Bonn
Germany
Phone: 0228 92994148
Email: info@podosara.de
2. General information on data processing
This website is designed as a purely informational website. We deliberately refrain from using analytics, tracking and advertising technologies, as well as embedded third-party content (such as social media plug-ins, embedded maps or videos). Personal data is only collected when you actively provide it to us – for example through a phone enquiry, by email, or when scheduling an appointment at the clinic.
3. Access data (server log files)
When you access our website, our hosting provider collects technically necessary access data in so-called server log files. This includes:
- the page requested and the amount of data transferred
- date and time of access
- the browser and operating system used
- referrer URL (the previously visited page)
- anonymised IP address
This data is processed solely to ensure the trouble-free operation of the website and to improve our service. It is not merged with other data sources or analysed for marketing purposes.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in providing a secure and functional website).
Retention period: Log files are usually deleted or anonymised automatically after no more than 7 days,
unless they are needed to investigate a specific security incident.
4. Cookies and local storage
This website does not use any analytics, tracking or advertising cookies, and does not embed any third-party cookies.
We only use technically necessary local storage (localStorage) in your browser to remember your acknowledgment of our cookie notice
so it is not shown to you again. Only the key praxis-cookie-ack with the value “1" is stored.
No data is transmitted to a server and no personal data is stored.
Legal basis: § 25 (2) no. 2 TTDSG (storage strictly necessary to provide the telemedia service expressly requested by the user).
5. Contact by phone or email
When you contact us by phone or email, the information you provide (name, contact details, your enquiry) will be processed to handle your request and for any follow-up questions.
Legal basis:
- Art. 6 (1) lit. b GDPR, if your enquiry is aimed at entering into a treatment contract or carrying out pre-contractual measures;
- Art. 6 (1) lit. f GDPR for other enquiries (legitimate interest in handling your request professionally).
Retention period: Your enquiry will be deleted once it has been conclusively handled, provided no statutory retention obligations apply. If a treatment relationship arises from the enquiry, statutory retention periods for medical records apply (generally 10 years after the end of treatment, § 630f German Civil Code).
Please note: unencrypted email communication is not protected against unauthorised access by third parties. Please therefore do not send us any sensitive health data via unencrypted email.
6. Treatment at the clinic
The processing of your personal and health data in connection with treatment at our clinic is not the subject of this website privacy policy. You will receive a separate patient privacy notice under Art. 13 GDPR at your first appointment.
7. Map showing the clinic location
On our contact page we deliberately avoid embedding Google Maps or OpenStreetMap directly. Instead, we display a static image of our location. When you click on the image, you will be redirected – depending on your device – to Apple Maps (on iOS devices) or Google Maps (on all other devices). Only when you actively click is data transmitted to the respective map provider.
Please refer to the privacy policies of the respective providers:
- Google Maps: policies.google.com/privacy
- Apple Maps: apple.com/legal/privacy
Legal basis: Art. 6 (1) lit. a GDPR (consent through your active click on the map link).
8. Links to external services (e.g. online appointment booking)
If our website contains links to external online appointment booking services (e.g. Doctolib, Noventi or similar), the privacy policy of the respective provider will apply once you click the link. No data is transferred to these services before you click.
9. Web fonts
This website uses fonts from Google Fonts (Quicksand, Inter), which are loaded on first access from the server fonts.googleapis.com
or fonts.gstatic.com within the European Union. When the fonts are loaded, your IP address is transmitted to Google.
According to Google, no cookies are stored and no personal tracking is performed for CSS requests to Google Fonts.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in a consistent and visually appealing presentation of our content). More information: policies.google.com/privacy.
10. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the browser's address bar shows “https://" and the lock icon is displayed.
11. Your rights as a data subject
You have the right at any time to:
- Access the personal data stored about you (Art. 15 GDPR);
- Rectification of inaccurate data (Art. 16 GDPR);
- Erasure of your data, provided no statutory retention obligations apply (Art. 17 GDPR);
- Restriction of processing (Art. 18 GDPR);
- Data portability (Art. 20 GDPR);
- Object to the processing of your data, where such processing is based on Art. 6 (1) lit. f GDPR (Art. 21 GDPR);
- Withdraw any given consent with effect for the future (Art. 7 (3) GDPR).
To exercise your rights, an informal message to the contact address above is sufficient.
12. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR (Art. 77 GDPR). The competent authority is in particular:
State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
(Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen)
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
Phone: +49 211 / 38424-0
Web: www.ldi.nrw.de
13. No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place on this website.
14. Currency and amendment of this privacy policy
This privacy policy is currently valid and has the status of May 2026. Due to the further development of our website or as a result of changes in legal or regulatory requirements, it may be necessary to amend this privacy policy. The current version can always be accessed on this page.