This is a courtesy translation of our German privacy policy. In the event of any discrepancy, the German version at hautmedizin-westend.de/datenschutz shall prevail.
Protecting your data matters to us – during medical treatment just as much as when you visit this website. Below we inform you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), which data we process, for what purpose and on what legal basis.
1. Controller
The controller within the meaning of Article 4 (7) GDPR is:
Joint medical practice (Berufsausübungsgemeinschaft) Dr. med. Johannes Benecke and Dr. med. Mario Giulini
Grüneburgweg 12, 60322 Frankfurt am Main, Germany
Telephone: +49 69 677 11 22
Email: kontakt@hautmedizin-westend.de
No data protection officer has been appointed, as the statutory conditions of Section 38 of the German Federal Data Protection Act are not currently met. For data protection enquiries, please contact us directly using the details above.
2. Data processing when you visit this website
When you access our pages, your browser automatically sends information to the server of our hosting provider, where it is stored temporarily in a log file:
- IP address of the requesting device
- Date and time of access
- Name and URL of the file retrieved
- Volume of data transferred and confirmation that the retrieval was successful
- Browser type and version, operating system
- Previously visited page (referrer), if your browser transmits it
This data is technically necessary in order to display the website to you, to ensure the stability and security of the system and to defend against attacks. The legal basis is Article 6 (1) sentence 1 (f) GDPR; our legitimate interest lies in the secure and trouble-free operation of this website. This data is not combined with other data sources and is not evaluated for advertising or analysis purposes. Log data is deleted after seven days at the latest, unless it is required to investigate a specific security incident.
3. No cookies, no analytics, no advertising networks
This website sets no cookies and stores no information on your device. No web analytics services, tracking tools, advertising networks, social media plug-ins or profiling procedures are used. Consent under Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) is therefore not required, and for the same reason this website needs no consent banner.
All fonts, images and videos are stored locally on our server and are not loaded from external providers. In particular, there is no connection to Google Fonts or any other content delivery network. No map is embedded either – the address on the contact page is merely linked.
4. Hosting
This website is hosted by:
IONOS SE
Elgendorfer Straße 57, 56410 Montabaur, Germany
www.ionos.de
IONOS processes the data listed under section 2 exclusively on our behalf and in accordance with our instructions; the servers are located within the European Union. This is governed by a data processing agreement pursuant to Article 28 GDPR. The legal basis for using an external hosting provider is Article 6 (1) sentence 1 (f) GDPR; our legitimate interest lies in providing this website securely, reliably and with professional support. Details of data processing at IONOS can be found in the provider’s own privacy information.
5. Encryption
For security reasons, this website uses TLS encryption. You can recognise an encrypted connection by the string “https://” in your browser’s address bar and by the padlock symbol. When encryption is active, the data you transmit to us cannot be read by third parties.
6. Contacting us by email or telephone
We deliberately do not offer a contact form. If you contact us by email or telephone, we process the information you provide solely in order to deal with your enquiry. The legal basis is Article 6 (1) sentence 1 (b) GDPR where your enquiry relates to the initiation or performance of a treatment contract, and otherwise Article 6 (1) sentence 1 (f) GDPR on the basis of our legitimate interest in responding to enquiries.
We delete this data once your enquiry has been dealt with conclusively and no statutory retention obligations apply. If you share health data with us, the provisions under section 8 apply in addition.
Unencrypted email is not a secure transmission channel. Please do not send us medical reports, diagnoses or photographs of skin lesions by email. In such cases, please call us.
7. Online appointment booking and external links
For online appointment booking we link to the portal operated by Doctolib GmbH, Mehringdamm 51, 10961 Berlin, Germany. This is a plain link – no Doctolib booking window or script is embedded in our website. As long as you do not click the link, no data whatsoever is transmitted to Doctolib.
Once you click, you leave our website. Doctolib is initially the controller for processing on the portal, and its own privacy policy applies there. Doctolib subsequently processes the appointment data collected during booking as a processor for our practice on the basis of an agreement pursuant to Article 28 GDPR. The servers are located within the European Union.
The same applies to other external links, such as those to our skincare services at skin-westend.de and to medical sources such as guideline registers or specialist literature databases. We have no influence on how they process data.
8. Processing of patient data at the practice
Independently of this website, we process your personal data in the course of treatment, including health data – that is, special categories of personal data within the meaning of Article 9 GDPR. This includes master data, insurance details, medical history, findings, diagnoses, photographic documentation, treatment and progress data, and billing data.
The legal bases are Article 9 (2) (h) in conjunction with Article 6 (1) sentence 1 (b) and (c) GDPR and Section 22 (1) no. 1 (b) of the German Federal Data Protection Act – processing takes place for the purposes of preventive healthcare, medical diagnosis and treatment by medical staff bound by professional secrecy under Section 203 of the German Criminal Code. For treatments without a medical indication, we base processing on your consent pursuant to Article 9 (2) (a) GDPR.
Where necessary in an individual case, recipients of your data may include: the association of statutory health insurance physicians and statutory health insurers, private medical billing services where you have consented, laboratories and pathology institutes, physicians involved in your co-treatment or onward treatment, pharmacies, and technical service providers for our practice management system and data backup, who are bound as processors under Article 28 GDPR. Any transfer to third parties beyond this takes place only with your consent or on the basis of a statutory obligation. No transfer to countries outside the European Union takes place.
We retain treatment records for ten years after completion of treatment in accordance with Section 630f (3) of the German Civil Code. Longer periods may result from other provisions, for example the Radiation Protection Ordinance or retention obligations under tax and commercial law. Providing your data is necessary for the treatment contract; without this information, proper treatment is not possible.
You will also receive this information in full detail at your first visit to the practice.
9. Your rights
You have the following rights with regard to the personal data concerning you:
- Access to the data processed (Article 15 GDPR)
- Rectification of inaccurate data or completion of incomplete data (Article 16 GDPR)
- Erasure (Article 17 GDPR), unless a statutory retention obligation applies
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR)
- Objection to processing based on legitimate interests (Article 21 GDPR)
- Withdrawal of consent with effect for the future (Article 7 (3) GDPR)
An informal message to the contact details given under section 1 is sufficient to exercise these rights. In order to protect your data, we must satisfy ourselves of your identity.
10. Right to lodge a complaint with a supervisory authority
Under Article 77 GDPR you have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (Hessian Commissioner for Data Protection and Freedom of Information)
Postfach 31 63, 65021 Wiesbaden
Office address: Wilhelmstraße 7, 65185 Wiesbaden
Telephone: +49 611 1408-0
datenschutz.hessen.de
11. Automated decision-making
Automated decision-making, including profiling, within the meaning of Article 22 GDPR does not take place.
12. Changes to this privacy policy
We update this privacy policy when the legal situation, our services or the technology behind this website change. The version available here applies to your visit.
Last updated: August 2026