Privacy Policy
Last updated: 7 September 2026
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Monika Groth, naturopathic practitioner (Heilpraktikerin)
c/o METAFELD
Schönhauser Allee 129
10437 Berlin
Email:
Further details can be found in the imprint. I have not appointed a data protection officer, as the statutory conditions for doing so do not apply.
2. Hosting
This website is hosted by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen. The data is processed in a data centre in Nuremberg and therefore within the European Union. The legal basis is my legitimate interest in providing this website securely and reliably (Art. 6(1)(f) GDPR). A data processing agreement in accordance with Art. 28 GDPR is in place with the provider.
3. Server log files
When this website is accessed, the web server automatically processes information that your browser transmits: the page accessed, the date and time, the volume of data transferred, browser type and version, operating system, referrer URL and IP address. This data is not merged with other data sources and is not used to identify individual persons. The logs are overwritten at regular intervals and are generally no longer available after 30 days at the latest. The legal basis is Art. 6(1)(f) GDPR (technically error-free and secure operation).
4. Cookies
This website does not use any marketing, advertising or statistics cookies. Only technically necessary cookies are set: a session cookie of the content management system and a token that protects the contact form against misuse. The legal basis is § 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(f) GDPR. These cookies contain no profiling data and become invalid when you close your browser at the latest. As no cookies requiring consent are used, this website does not need a cookie consent banner.
5. Contact form
If you write to me using the contact form, I process the data you enter – your name, email address, optionally your telephone number and your message – in order to answer your enquiry and to offer you an appointment. Mandatory fields are marked as such; before sending, you confirm that you have read this privacy policy.
The legal basis is Art. 6(1)(b) GDPR where your enquiry is aimed at a consultation (steps prior to entering into a contract), and otherwise Art. 6(1)(f) GDPR (legitimate interest in dealing with enquiries). Where you provide information about your health in the form, the processing takes place on the basis of your consent (Art. 9(2)(a) GDPR), which you can withdraw at any time with effect for the future.
Your entries are transmitted by email to my mailbox and are additionally stored in the form database of this website; you will receive a confirmation of receipt at the address you have given. I delete the data as soon as your enquiry has been dealt with conclusively and no statutory retention obligations prevent this.
6. Spam protection
To protect the form against automated submissions, I use a proof-of-work check: your browser solves a small computing task in the background, and you do not have to answer a picture puzzle. The check runs entirely on my own server; no data is transferred to third-party providers, no cookies are set and no user tracking is carried out. The legal basis is Art. 6(1)(f) GDPR (protection against spam and misuse).
7. Contacting me by email or telephone
If you contact me by email or by telephone, I process your details solely in order to deal with your request. The legal basis is Art. 6(1)(b) GDPR for consultation-related enquiries, otherwise Art. 6(1)(f) GDPR. I delete the data as soon as your request has been settled and no retention obligations apply.
8. Online appointment booking with Calendly
For arranging appointments I use the Calendly service provided by Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA. The appointment calendar is not embedded in this website; it opens only when you open it in a new window via the button – no data is transferred to Calendly before that. When it loads and when you make a booking, Calendly processes your IP address, browser data and the details you enter (name, email address, chosen appointment, optional notes). The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG) and the arrangement of the appointment (Art. 6(1)(b) GDPR). Calendly is certified under the EU-US Data Privacy Framework; the transfer of data to the USA is based on the adequacy decision of the European Commission. Details: Calendly’s privacy policy.
9. Data processing in the context of the online consultation
I process personal data collected in the course of the online consultation and of laboratory tests (e.g. name, date of birth, contact details, the content of our conversations, findings, laboratory samples) in order to carry out the consultation, to draw up individual treatment plans and to document the course of treatment. The legal bases are Art. 6(1)(b) GDPR (performance of a contract) and Art. 9(2)(h) GDPR (health data for the purposes of health care).
The consultations take place by video call (Zoom, Microsoft Teams or Google Meet) or by telephone. The communication is encrypted; conversations are not recorded. We agree in advance which tool is used; the privacy notice of the respective provider applies to the data processing carried out by that provider (Zoom, Microsoft Teams, Google Meet).
For laboratory tests, the necessary personal data is passed on to the laboratory Biovis Diagnostik MVZ (Art. 6(1)(b) and Art. 9(2)(h) GDPR). I keep laboratory findings and consultation records for ten years (§ 630f BGB, § 147 AO); other communication data I delete after six months, provided that no retention obligation applies.
10. No web analytics, no tracking
No measurement of reach and no analysis of your usage behaviour takes place on this website. I use neither Google Analytics nor any comparable analytics, advertising or tracking service. No usage profiles are created, no cross-site tracking takes place and no automated decision-making is carried out. Should I use anonymous measurement of reach in future, I will amend this privacy policy accordingly beforehand.
11. No social media plugins, fonts hosted locally
No social media plugins are embedded in this website. The fonts used are delivered locally from my own server; there is no connection to Google Fonts or to other font providers. Apart from the appointment calendar described in section 8, which is only loaded after a click, no third-party content is embedded.
12. SSL and TLS encryption
For security reasons and in order to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of the browser begins with “https://” and a padlock symbol is displayed.
13. Recipients and transfers to third countries
I only pass on your data where this is necessary in order to fulfil contractual or statutory obligations. The recipients are the hosting provider Hetzner Online GmbH as a processor (section 2), the operator of the email service, ALL-INKL.COM – Neue Medien Münnich, Inh. René Münnich, Hauptstraße 68, 02742 Friedersdorf, through which form and contact emails are sent and stored in the mailbox, the laboratory Biovis Diagnostik MVZ (section 9) and – only after you have activated it – Calendly LLC (section 8). Beyond this, no transfer to countries outside the European Union takes place.
14. Your rights as a data subject
You have the following rights in relation to me with regard to the personal data concerning you:
- access to the data processed (Art. 15 GDPR)
- rectification of inaccurate or incomplete data (Art. 16 GDPR)
- erasure of your data (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability in a commonly used, machine-readable format (Art. 20 GDPR)
- objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
An informal message to
15. Right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR). The competent authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information), Alt-Moabit 59-61, 10555 Berlin, www.datenschutz-berlin.de.
16. Changes to this privacy policy
I will amend this privacy policy as soon as changes to this website or to the legal situation make this necessary. The version published here applies in each case.