As of September 2026
This Privacy Policy informs you of the nature, scope, and purpose of the processing of personal data by the companies of the Clinomic Group when you use our website clinomic.ai, our online services, our recruitment portal, or when engaging in existing or prospective business relationships with our customers, suppliers, and business partners.
1. Data Controller and Intragroup Data Processing
The Data Controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Clinomic Group GmbH
Forckenbeckstraße 66
52074 Aachen, Germany
Phone: +49 241 89430737
Email: info@clinomic.ai
Intragroup Data Processing within the Clinomic Group:
Clinomic Group GmbH operates this website and central IT systems for all entities of the Clinomic Group (in particular Clinomic Medical GmbH).
Insofar as data collected via this website or during operational business activities (e.g., product inquiries regarding the Mona platform, appointment bookings, customer and supplier data, or applicant records) are forwarded to the respective operational subsidiaries or jointly used within centralized systems (CRM, HR tools, ERP), this processing is conducted on the basis of intragroup Data Processing Agreements (Art. 28 GDPR) or Joint Controller Agreements (Art. 26 GDPR).
2. Data Protection Officer
You can contact our central external Data Protection Officer for all entities of the Clinomic Group at:
Email: dpo@clinomic.ai
Postal Address: Clinomic Group GmbH, attn.: Data Protection Officer, Forckenbeckstraße 66, 52074 Aachen, Germany
3. Subject Matter and Sources of Data Processing
The subject matter of data protection is personal data pursuant to Art. 4 No. 1 GDPR (any information relating to an identified or identifiable natural person).
Direct Collection: We process personal data provided directly by you (e.g., via inquiry forms, contract conclusions, appointment bookings, or job applications).
Collection from Third Parties / Public Sources: Where necessary, we process personal data lawfully obtained from publicly accessible sources (e.g., commercial and association registers, press releases, corporate websites, professional networks such as LinkedIn or Xing) or legitimately transferred to us by third parties (e.g., credit agencies, partners).
4. Provision of the Website and Server Log Files
When visiting our website clinomic.ai, our system automatically collects data from the accessing device:
Browser type and version, operating system used
Referrer URL (the previously visited page), hostname of the accessing computer
Date and time of the server request, IP address of the accessing device
Legal Basis & Purpose: Technically necessary for the delivery of the website and to ensure IT security and system stability (Art. 6(1)(f) GDPR).
Web Hosting: The website is hosted on servers operated by RAIDBOXES GmbH, Friedrich-Ebert-Straße 7, 48153 Münster, Germany, pursuant to a Data Processing Agreement (Art. 28 GDPR) within the EU.
Storage Duration: Server log files are automatically deleted or anonymized after a maximum of 90 days.
5. Bot Protection & Content Delivery Network (Cloudflare)
We utilize the security and performance service Cloudflare provided by Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Purpose: Protection against malicious attacks (e.g., bot mitigation via the __cf_bm cookie) and fast delivery of website content via a global Content Delivery Network.
Legal Basis: Sec. 25(2) No. 2 TDDDG (Telecommunications Digital Services Data Protection Act) in conjunction with Art. 6(1)(f) GDPR (legitimate interest in IT security). Cloudflare Inc. is certified under the EU-U.S. Data Privacy Framework (DPF).
6. Consent Management (CookieYes)
To manage data protection consent preferences, we use the consent management tool CookieYes (CookieYes Limited, 3 The Drive, Jubilee House, Great Warley, Brentwood, CM13 3FR, United Kingdom).
Functionality: Storage of consent cookies (cookieyes-*, cookietest) to record and maintain your consent choices (Opt-In / Opt-Out).
Legal Basis: Compliance with a legal obligation pursuant to Art. 6(1)(c) GDPR in conjunction with Sec. 25(2) No. 2 TDDDG and Art. 7(1) GDPR. An adequacy decision pursuant to Art. 45 GDPR applies to the United Kingdom.
7. Tag Management (Google Tag Manager)
We use the Google Tag Manager provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).
Functionality: Google Tag Manager is an auxiliary service that does not place cookies itself and does not store personal data. It triggers other scripts, which are strictly loaded only after your explicit consent has been granted via the CookieYes banner.
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in efficient website tag management).
8. Web Analytics: Google Analytics 4 (incl. Google Signals)
We use the web analytics service Google Analytics 4 provided by Google Ireland Limited.
Features: Use of analytics cookies (_ga, _ga_*) with activated IP anonymization. Subject to your consent, Google Analytics 4 also processes cross-device data and aggregated audience insights via “Google Signals”.
Legal Basis: Sec. 25(1) TDDDG (access to end-user device) in conjunction with Art. 6(1)(a) GDPR (consent). Google LLC (USA) is certified under the EU-U.S. Data Privacy Framework (DPF).
9. Online Marketing & Conversion Tracking
9.1 Google Ads Conversion Tracking (incl. Enhanced Conversions) & Remarketing
Enhanced Conversions: Where consented, form data (e.g., email addresses) is pseudonymized (hashed) prior to transmission to Google to measure ad conversion effectiveness securely.
Remarketing: Display of interest-based advertisements across third-party websites within the Google advertising network (_gcl_au, test_cookie).
Legal Basis: Sec. 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
9.2 Microsoft Ads (Universal Event Tracking – UET)
We use conversion tracking from Microsoft Ads (Microsoft Ireland Operations Limited, Dublin, Ireland). Microsoft places cookies (_uetsid, _uetvid, MUID) to track user interactions after clicking a Bing advertisement.
Legal Basis: Sec. 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Microsoft Corporation (USA) is DPF-certified.
10. HubSpot (CRM, Forms & Marketing Automation)
We use the integrated platform HubSpot (HubSpot Ireland Limited / HubSpot Inc., USA) for marketing automation, email communication, contact forms, and web analytics (__hstc, hubspotutk, __hssc, __hssrc).
Legal Basis: Sec. 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR for analytics/tracking cookies; Art. 6(1)(b)/(f) GDPR for form inquiries and customer relationship management. HubSpot Inc. is DPF-certified.
11. Online Appointment Booking (Odoo Appointment)
For online scheduling, we use Odoo Appointment provided by Odoo S.A., Chaussée de Namur 40, 1367 Grand-Rosière, Belgium.
Redirection: Clicking the scheduling button redirects you to our external booking portal clinomic-appointment.odoo.com.
Processed Data: First and last name, email address, phone number (optional), company/clinic name, reason for and time of appointment. Only strictly necessary session cookies (session_id, frontend_lang, tz) are set on the booking page. No advertising tracking takes place.
Legal Basis: Art. 6(1)(b) GDPR in conjunction with Sec. 25(2) No. 2 TDDDG. A Data Processing Agreement pursuant to Art. 28 GDPR is in place; data is stored exclusively on EU servers.
12. Job Applications and Career Portal (GoHire)
When applying for employment, we process your submitted documents (name, contact information, resume/CV, certificates, timestamp of application).
Platform GoHire: We use GoHire (GoHire Technologies LTD, UK) as a Data Processor pursuant to Art. 28 GDPR (covered by the UK Adequacy Decision under Art. 45 GDPR).
Legal Basis: Sec. 26(1) German Federal Data Protection Act (BDSG) in conjunction with Art. 6(1)(b) GDPR (initiating an employment relationship).
Retention & Erasure: In the event of a rejection, applicant data is automatically deleted after exactly 6 months following completion of the application process to comply with legal retention requirements (AGG). Storage in our Talent Pool (> 6 months) occurs exclusively subject to your explicit consent (Art. 6(1)(a) GDPR).
13. Embedded Media (YouTube)
Videos from the YouTube platform (Google Ireland Limited) are embedded on our website and loaded only after your active consent via the CookieYes banner (VISITOR_*, YSC, __Secure-*).
Legal Basis: Sec. 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
14. Social Media Presences
We maintain public profiles on social networks to communicate with customers and interested parties:
LinkedIn: LinkedIn Ireland Unlimited Company, Dublin, Ireland. Joint controllership applies to Page Insights data pursuant to Art. 26 GDPR ([https://legal.linkedin.com/pages-joint-controller-addendum](https://legal.linkedin.com/pages-joint-controller-addendum)).
X (formerly Twitter): Twitter International Company, Dublin, Ireland.
Legal Basis: Legitimate interest in corporate communication and marketing pursuant to Art. 6(1)(f) GDPR.
15. Privacy Information for Business Partners, Customers & Suppliers (B2B)
This section applies to the processing of personal data of natural persons acting on behalf of or representing our contractual partners, customers, suppliers, service providers, or media partners.
15.1 Categories of Processed Data
Personal details (name, title, position/function within the company)
Contact information (business email address, business phone/mobile number, postal address)
Contractual and transaction data (sales figures, payment/bank details, tax IDs, order history)
Correspondence and communication logs generated during the business relationship
15.2 Purposes and Legal Bases of Processing
Consent (Art. 6(1)(a) GDPR): Where requested for specific purposes (e.g., event registration).
Contract Performance & Pre-contractual Measures (Art. 6(1)(b) GDPR): Executing contracts with sole proprietors or freelancers.
Legal Obligations (Art. 6(1)(c) GDPR): Compliance with tax, accounting, anti-money laundering, and statutory retention laws.
Legitimate Interests (Art. 6(1)(f) GDPR):
Initiating, managing, and processing contracts with corporate entities/employers.
Maintaining Customer and Supplier Relationship Management (CRM) systems.
Conducting credit rating checks to mitigate default risks in procurement/sales.
Establishing, exercising, or defending legal claims.
Ensuring operational, physical, and IT system security.
B2B Direct Email Marketing (Sec. 7(3) German Act Against Unfair Competition – UWG in conjunction with Art. 6(1)(f) GDPR): We process business email addresses of existing customers to inform them about similar products or services, provided you have not objected to such communications.
16. Recipients and Transfer of Personal Data
We transfer personal data to third parties strictly within the boundaries of applicable law:
Group Entities: Clinomic Group GmbH, Clinomic Medical GmbH, Clinomic Solutions GmbH, Clinomic Telemedicine GmbH, Clinomic Romania SRL for internal administration based on intragroup agreements (Art. 26/28 GDPR).
Data Processors: External service providers (IT hosting, CRM, recruitment, legal and tax advisors) bound by Data Processing Agreements pursuant to Art. 28 GDPR.
Public Authorities: Government agencies, tax authorities, and law enforcement agencies when legally mandated (Art. 6(1)(c) GDPR).
17. International Data Transfers
Where personal data is transferred to third countries outside the European Economic Area (EEA), we ensure appropriate safeguards:
An Adequacy Decision by the EU Commission is in place (e.g., UK adequacy, or US companies certified under the EU-U.S. Data Privacy Framework pursuant to Art. 45 GDPR), or
EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR have been executed alongside necessary supplementary technical measures.
18. Storage Duration and Erasure
Personal data is erased or anonymized as soon as the processing purpose no longer applies.
B2B & Contractual Data: Stored for the duration of the business relationship and retained for 6 to 10 years in accordance with commercial (HGB) and tax (AO) retention laws.
Applicant Data: Erased after exactly 6 months in the event of a rejection (Sec. 26 BDSG / AGG).
Server Log Files: Automatically erased after 90 days.
Consent Documentation: Retained for 3 years following revocation pursuant to Art. 7(1) GDPR in conjunction with Art. 6(1)(c) GDPR.
19. Your Rights as a Data Subject
Under Art. 15–22 GDPR, you possess the following rights regarding your personal data:
Right of Access (Art. 15 GDPR / Sec. 34 BDSG)
Right to Rectification (Art. 16 GDPR)
Right to Erasure (Art. 17 GDPR / Sec. 35 BDSG)
Right to Restriction of Processing (Art. 18 GDPR)
Right to Data Portability (Art. 20 GDPR)
Right to Object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Art. 6(1)(f) GDPR.
Right to Withdraw Consent (Art. 7(3) GDPR): You may withdraw ergranted consent at any time with future effect.
Right to Object to Direct Marketing: You can object to the processing of your data for direct marketing purposes at any time free of charge.
Competent Supervisory Authority:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2-4, 40213 Düsseldorf, Germany
Phone: +49 211 38424-0 | Email: poststelle@ldi.nrw.de