Privacy Policy

1) Introduction and Contact Details of the Controller

We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data is any data with which you can be personally identified.

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Utku Pul, Kullrichstr. 10, 44141 Dortmund, Germany, Tel.: +491738235070, Email: info@pulszahnmedizin.de. The controller responsible for the processing of personal data is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

Contact for data protection inquiries: info@pulszahnmedizin.de. An external data protection officer (DPO) will be appointed before the physical practice opening on 01.01.2027; this privacy policy will be updated accordingly at that time. Self-appointment of the controller as their own DPO is excluded under Art. 38(6) GDPR.

2) Data Collection When Visiting Our Website

When using our website for informational purposes only, i.e., if you do not register or otherwise provide us with information, we only collect the data that your browser transmits to the page server (so-called 'server log files'). When you access our website, we collect the following data that is technically necessary for us to display the website:

  • Our visited website
  • Date and time of access
  • Amount of data sent in bytes
  • Source/reference from which you reached the page
  • Browser used
  • Operating system used
  • IP address used (if applicable: in anonymized form)

Processing is carried out pursuant to Art. 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data is not passed on or used in any other way. However, we reserve the right to subsequently review the server log files if there are specific indications of unlawful use.

For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string 'https://' and the lock symbol in your browser line.

3) Hosting on Vercel (EU)

This website is hosted with Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Content delivery and request processing take place via Vercel's edge network, regionalised in the EU (primary processing in Frankfurt, region fra1). When you access the site, technically necessary connection data (IP address, date/time of the request, transmitted byte count, user-agent, HTTP status) is processed in order to deliver the website and to protect it from abuse. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the stable, secure operation of the website). We have concluded a data processing agreement (Data Processing Addendum) with Vercel pursuant to Art. 28 GDPR. Because Vercel Inc. is headquartered in the USA, transfers to the USA may occur as part of internal corporate functions; these are based on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and Vercel's certification under the EU-US Data Privacy Framework. Vercel retains logfiles for a maximum of 30 days.

4) Cookies

This website does not set any cookies that require consent. Only a single, technically necessary cookie named 'NEXT_LOCALE' is used. It stores solely your chosen language (de/en/tr) so that the site can be displayed in the correct language version on your next visit. It does not contain any personally identifiable data and is not used for tracking, advertising or analytics.

The legal basis for setting this cookie is Section 25(2)(2) TDDDG (strictly necessary to provide the telemedia service expressly requested by the user). Consent is not required. You can delete the cookie at any time via your browser settings.

5) Contact

5.1 Contact form and email

Our contact page provides a contact form. When you submit the form, the data you enter (name, email address, optional phone number and practice/company name, the content of your message) along with your GDPR consent and technical metadata (IP address, user-agent, timestamp) are transmitted to our server at the path /api/kontakt and forwarded immediately by email to info@pulszahnmedizin.de. The submission is not stored in any database (data minimisation pursuant to Art. 5(1)(c) GDPR). Alternatively, you can still write to us directly by email at info@pulszahnmedizin.de. The legal basis for processing is your explicit consent pursuant to Art. 6(1)(a) GDPR; additionally Art. 6(1)(b) GDPR for pre-contractual enquiries and Art. 6(1)(f) GDPR (legitimate interest in answering your enquiry). Both the dispatch and the receiving mailbox are handled via our email service provider Mailbox.org Eversmann SE, Mehringdamm 33, 10961 Berlin, Germany (servers in Germany; data processing agreement under Art. 28 GDPR concluded). We delete your enquiry once the underlying matter is conclusively resolved and there are no statutory retention obligations to the contrary.

5.2 WhatsApp (wa.me link)

Our website includes a link that, when clicked, opens the WhatsApp application on your device and prepares a new chat with our mobile number +49 151 44903794 (so-called wa.me deeplink). We use neither an embedded WhatsApp plugin, nor the WhatsApp Business API, nor address-book synchronisation. Only when you actively send a message do you contact us via the WhatsApp infrastructure (operator: WhatsApp Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland).

If you contact us via WhatsApp, we process the data you supply (in particular your mobile number and the content of your message) in order to handle your enquiry on the basis of Art. 6(1)(f) GDPR (legitimate interest in a timely response). If your message concerns a pre-contractual measure or a contract, Art. 6(1)(b) GDPR also applies.

Please note that the content and metadata of your WhatsApp messages may be processed via the WhatsApp infrastructure and therefore also via servers of Meta Platforms Inc. in the USA. We have no influence over this processing. Transfers to the USA are based on the EU-US Data Privacy Framework. WhatsApp's privacy notice is available at: https://www.whatsapp.com/legal/?eea=1#privacy-policy. If you wish to avoid this processing, please use email or telephone instead.

5.3 Link to Instagram

Our website contains a simple outbound link to our Instagram profile (operator: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland). No Instagram plugin is embedded, no content is loaded automatically, and no Shariff-style solution is used. Only when you actively click the link are you redirected to the Instagram website, where Meta's privacy terms then apply.

6) AI Reception Assistance in the Practice (PAIRA Avatar)

6.1 Description

An AI-supported reception kiosk (internal name: PAIRA Avatar) may be used in the practice rooms. A digital avatar is shown on a screen in the reception area; it can greet you, record your request and forward it to the practice team. Input is provided by voice or via a tablet/control panel used by staff.

6.2 Data Processed

  • Audio stream during the interaction for real-time processing; no persistent audio recording is made.
  • Spoken request or text input on the tablet/control panel.
  • Raw transcript of the interaction, where technically necessary to handle and verify the request.
  • For identified existing patients: name, date of birth and patient number from the local Tomedo practice management system, only where necessary.
  • Tool and forwarding events, e.g. hand-off to staff or creation of a task.

6.3 Purposes and Legal Basis

Processing serves reception organisation, recording your request and initiating or performing the treatment contract (Art. 6(1)(b) GDPR). Where health data is processed, processing is based on Art. 9(2)(h) GDPR (health care). PAIRA does not provide medical diagnoses, health triage or treatment decisions; treatment-related decisions are made exclusively by licensed practitioners.

6.4 Processors and Sub-Processors

  • BodoTech UG (haftungsbeschränkt), Dortmund: software operation and maintenance on behalf of the practice (DPA pursuant to Art. 28 GDPR).
  • Google Cloud (Google Ireland Ltd.): Vertex AI Gemini Live for speech processing in the europe-west1 region (Belgium), with zero-data-retention configuration and no use of audio or transcript data for model improvement.

6.5 Retention Period

  • Audio stream: real-time processing without persistent audio recording.
  • Raw transcript: no more than 24 hours.
  • Local Gemma summary: a local Gemma LLM may, where medically or operationally necessary, store a purpose-bound summary as a note in Tomedo or in the patient record. This note is not raw transcript retention and follows the rules for treatment documentation or patient records.
  • Tool and audit metadata without conversation content is stored for purpose-bound audit and documentation obligations.

A data protection impact assessment (DPIA) pursuant to Art. 35 GDPR is available and can be inspected with the practice management.

7) AI Telephone Reception (PAIRA Calls)

7.1 Description

Calls to the practice phone number may be answered outside consultation hours or during call peaks by an AI-supported telephone reception service (internal name: PAIRA Calls). At the beginning of each call you are informed about the AI support and referred to this privacy policy. You may hang up at any time or ask for a human staff member; in that case your request is recorded as a message or callback request.

7.2 Data Processed

  • Phone number or caller ID, time, duration and technical status of the call.
  • Audio stream during the call for real-time processing; no persistent audio recording is made.
  • Raw transcript of the call to handle the request and for short-term quality and safety traceability.
  • If identified as an existing patient: name, date of birth and patient number from the local Tomedo practice management system, only where necessary.
  • Description of the request, e.g. appointment type, callback request, organisational notes or symptoms mentioned by the caller.
  • Tool calls and audit metadata, e.g. appointment booked, cancelled, rescheduled or callback task created.

7.3 Purposes and Legal Basis

Processing serves answering and handling your calls, appointment organisation, callback coordination and initiating or performing the treatment contract (Art. 6(1)(b) GDPR). Where health data is processed, Art. 9(2)(h) GDPR applies; in the event of acute emergency indicators, forwarding to human practitioners may be based on Art. 6(1)(d) and Art. 9(2)(c) GDPR. Audit and security checks are based on Art. 6(1)(f) GDPR. PAIRA does not make diagnoses, perform health triage or make treatment decisions.

7.4 Processors and Sub-Processors

  • BodoTech UG (haftungsbeschränkt), Dortmund: software operation and maintenance on behalf of the practice (DPA pursuant to Art. 28 GDPR).
  • Starface GmbH: SIP trunk and telephone connection for production operation; Germany location, DPA pursuant to Art. 28 GDPR.
  • Hetzner Online GmbH, Falkenstein: hosting of the telephone bridge or LiveKit components, where used (DPA pursuant to Art. 28 GDPR).
  • Google Cloud (Google Ireland Ltd.): Vertex AI Gemini Live for speech processing in the europe-west1 region (Belgium), with zero-data-retention configuration and no use of audio or transcript data for model improvement.

7.5 Retention Period

  • Audio recording: no persistent audio recording is made.
  • Raw transcript: no more than 24 hours.
  • Call metadata and tool/audit metadata without conversation content is stored for purpose-bound audit and documentation obligations.
  • Local Gemma summary: a local Gemma LLM may, where medically or operationally necessary, store a purpose-bound summary as a note in Tomedo or in the patient record. This note is not raw transcript retention and follows the rules for treatment documentation or patient records.
  • Vertex AI / Google Cloud processes real-time data with zero-data-retention configuration; the data is not used for model improvement.

7.6 Choice

You can decline the AI telephone reception by hanging up or expressly asking during the call for a human staff member. In that case your request is recorded as a message or callback request for the practice team.

A data protection impact assessment (DPIA) pursuant to Art. 35 GDPR is available and can be inspected with the practice management.

8) Newsletter / Waitlist

Sign-up for our opening waitlist

Our website allows you to sign up for our opening waitlist / newsletter. The responsible operator is Pulszahnmedizin (see above). Technical implementation is provided by our processor Bodo Tech UG (haftungsbeschränkt), Kullrichstr. 10, 44141 Dortmund, Germany (DPA pursuant to Art. 28 GDPR). The confirmation email (double opt-in) is sent via SMTP through our email service provider Mailbox.org Eversmann SE, Mehringdamm 33, 10961 Berlin, Germany (servers in Germany; DPA concluded under Art. 28 GDPR). After you confirm the double opt-in, your entry is handed off to our list service provider Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany); processing takes place on servers within the European Union (Germany and France). Brevo is listed as a sub-processor in our DPA with Bodo Tech. On sign-up the following data is collected and processed: email address, preferred language (German/Turkish/English), sign-up source, and the date and time of sign-up. To protect the double-opt-in flow against abuse we use a cryptographic HMAC token in the confirmation email; this serves purely technical and security purposes and is not used for profiling. The legal basis is your express consent pursuant to Art. 6(1)(a) GDPR. You may unsubscribe at any time via the unsubscribe link in any newsletter email or by sending a message to info@pulszahnmedizin.de. After unsubscribing, your email address is removed from the active distribution list without delay. More information on data protection at Brevo: https://www.brevo.com/de/legal/privacypolicy/. Mailbox.org's privacy notice: https://mailbox.org/de/datenschutz.

9) Job applications (Careers)

Through the application form on our careers page you can apply for positions at our practice. We process: first and last name, email address, telephone number (optional), the application documents you upload (CV as a mandatory document plus up to three references/certificates as optional attachments, in PDF/JPEG/PNG, max. 8 MB total), and any free-text message. Submission is delivered to us by email at info@pulszahnmedizin.de via our SMTP provider Mailbox.org Eversmann SE, Mehringdamm 33, 10961 Berlin, Germany (servers in Germany; DPA under Art. 28 GDPR concluded). The legal basis for processing is Section 26(1) sentence 1 of the German Federal Data Protection Act (BDSG) in conjunction with Art. 88 GDPR, as well as Art. 6(1)(b) GDPR (initiation of an employment relationship). If we are able to consider your application, your data is used to conduct the application process. If your application is not successful, your application documents are deleted no later than six months after the conclusion of the application process, unless a longer retention period is necessary for reasons of evidence under the German General Equal Treatment Act (Section 15 AGG) or you have expressly consented to longer storage (e.g. inclusion in an applicant pool).

10) Reach measurement (cookieless analytics)

10.1 Plausible Analytics

This website uses 'Plausible Analytics', a cookieless web analytics tool by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia (EU). Plausible sets no cookies and does not collect any personal data or personally identifiable identifiers. Only aggregated reach statistics are collected (page views, visitor counts, approximate location at country level, dwell time, referrer, anonymised device/browser class). The IP address is not stored at any time; it is used only briefly server-side, in the form of a hash with a daily rotating salt, to generate an aggregated daily count, and is then discarded after 24 hours. Processing takes place on servers within the European Union. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a data-minimising, cookieless reach measurement, in line with the DSK Orientierungshilfe Telemedien 2.0). Because Plausible technically does not read or store device or browser information, consent under Section 25 TDDDG is not required. You may object to this processing at any time pursuant to Art. 21 GDPR by writing to info@pulszahnmedizin.de. Plausible's privacy notice: https://plausible.io/privacy.

10.2 Vercel Web Analytics

We additionally use 'Vercel Web Analytics' by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. This service is also fully cookieless and collects aggregated usage data on page views, performance metrics (Core Web Vitals) and approximate geo-information at country level. No profiling takes place; no persistent personally identifiable identifier (e.g. cross-device ID) is created. IP addresses are anonymised by Vercel and not stored. Initial processing takes place on Vercel edge servers within the EU; as part of internal corporate functions, data flows to Vercel Inc. in the USA may occur, secured by Standard Contractual Clauses (Art. 46(2)(c) GDPR) and the EU-US Data Privacy Framework certification. We have concluded a data processing agreement with Vercel pursuant to Art. 28 GDPR. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in ensuring performance, stability and aggregated reach measurement). You may object to this processing at any time pursuant to Art. 21 GDPR by writing to info@pulszahnmedizin.de. Vercel's privacy notice: https://vercel.com/legal/privacy-policy.

11) Directions / Maps

On our contact page you will find a simple outbound link that, when clicked, redirects to the OpenStreetMap website (operator: OpenStreetMap Foundation, St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom) showing our address. No interactive map is embedded, no third-party content is loaded, and no connection to map servers is established as long as you do not actively click the link. Only after your click do the privacy terms of the respective provider apply. We do not use Google Maps or any other embedded map service.

12) Rights of the Data Subject

Applicable data protection law grants you the following data subject rights (rights of access and intervention) vis-a-vis the controller with regard to the processing of your personal data, whereby for the respective exercise requirements, reference is made to the cited legal basis:

  • Right of access pursuant to Art. 15 GDPR
  • Right to rectification pursuant to Art. 16 GDPR
  • Right to erasure pursuant to Art. 17 GDPR
  • Right to restriction of processing pursuant to Art. 18 GDPR
  • Right to notification pursuant to Art. 19 GDPR
  • Right to data portability pursuant to Art. 20 GDPR
  • Right to withdraw consent pursuant to Art. 7(3) GDPR
  • Right to lodge a complaint pursuant to Art. 77 GDPR

Competent supervisory authority

You may exercise your right to lodge a complaint under Art. 77 GDPR in particular before the supervisory authority competent for us: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, https://www.ldi.nrw.de.

RIGHT TO OBJECT

IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTEREST IN THE CONTEXT OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED. HOWEVER, FURTHER PROCESSING IS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING SERVES THE ASSERTION, EXERCISE OR DEFENSE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR THE PURPOSE OF SUCH MARKETING. YOU MAY EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.

13) Duration of Storage of Personal Data

The duration of storage of personal data is determined by the respective legal basis, the processing purpose and - if applicable - additionally by the respective statutory retention period (e.g., commercial and tax law retention periods).

When processing personal data on the basis of express consent pursuant to Art. 6(1)(a) GDPR, the data concerned is stored until you revoke your consent.

If statutory retention periods exist for data processed in the context of legal or similar obligations on the basis of Art. 6(1)(b) GDPR, this data is routinely deleted after the retention periods have expired, provided it is no longer necessary for contract performance or contract initiation and/or there is no legitimate interest on our part in continued storage.

When processing personal data on the basis of Art. 6(1)(f) GDPR, this data is stored until you exercise your right to object pursuant to Art. 21(1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the assertion, exercise or defense of legal claims.

When processing personal data for the purpose of direct marketing on the basis of Art. 6(1)(f) GDPR, this data is stored until you exercise your right to object pursuant to Art. 21(2) GDPR.

Unless otherwise stated in the other information in this statement about specific processing situations, stored personal data is otherwise deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.

14) No Automated Decision-Making Within the Meaning of Art. 22 GDPR

There is no decision-making based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.

Clarification regarding the AI-supported reception systems: PAIRA Avatar and PAIRA Calls implement explicit requests from visitors or callers, e.g. booking, rescheduling or cancelling an appointment, or recording a callback request. PAIRA does not make an independent decision about a data subject. There is no credit check, health triage, diagnosis or assessment by PAIRA. All treatment-related decisions are made exclusively by the practice's licensed practitioners.

This privacy policy is based on a template by IT-Recht Kanzlei (https://www.it-recht-kanzlei.de) and has been fully adapted to the actual data flows of this website. Last updated: May 2026.

Last updated: May 2026