Security and data protection

Our platforms carry statutory care traffic. That sets the bar: German data centres, no personal data outside the EU, encrypted transport throughout, and a video service certified under Anlage 31b BMV-Ä.

Where your data lives

Hosted in Germany

Our platforms run on SysEleven infrastructure in German data centres. SysEleven, a subsidiary of secunet Security Networks AG, operates six georedundant data centres in Germany and holds ISO 27001 (on the basis of BSI IT-Grundschutz), ISO 27017, ISO 27018 and BSI C5 for that infrastructure.

No third-country transfer

No personal data is passed to countries outside the EU or the EEA, or to international organisations.

Processors under Art. 28 GDPR

Service providers who process personal data on our behalf are bound by a data processing agreement and act strictly on our instructions.

Encryption in transit

HTTPS everywhere

Every connection to our platforms runs over HTTPS. There is no unencrypted access path — not for the admin interface, not for the API, not for the patient.

WebRTC for video

Video consultations use WebRTC. Audio and video are transported over DTLS-SRTP; WebRTC does not permit unencrypted media transport.

A certified video service

Our video service meets the requirements of Anlage 31b BMV-Ä. The proof rests on three pillars.

A certificate from a certification body accredited under ISO/IEC 17065 for the technical procedures for video consultations under § 365 (1) SGB V. The accreditation is established in agreement with the German Federal Office for Information Security (BSI).

How long we keep data

Video consultations

Name and e-mail address, the internal database ID and the billing metadata — date, time and duration of the call. Stored for three months, then automatically anonymised.

Visiting the website

If you only browse our site, your personal data is deleted as soon as you leave. Functional cookies go with it.

Questions from procurement

The answers we are asked for most often when a tender or a data protection review is running.

On SysEleven infrastructure in German data centres. SysEleven is a subsidiary of secunet Security Networks AG and operates six georedundant data centres in Germany, certified to ISO 27001 on the basis of BSI IT-Grundschutz, ISO 27017, ISO 27018 and BSI C5. No personal data is passed to countries outside the EU or the EEA, or to international organisations.

We use service providers in four categories: video and voice technology, the technical infrastructure the platform runs on, payment processing, and — where claims have to be enforced — legal advisers and collection agencies. Providers who process personal data on our behalf act as processors under Art. 28 GDPR, bound by a data processing agreement and strictly by our instructions. The current list is supplied on request.

For statutory video consultations, the participant’s name and e-mail address, the internal database ID and the billing metadata — date, time and duration — are stored for three months and then automatically anonymised. If someone only browses the website, their personal data is deleted as soon as they leave. Commercial and tax retention periods remain unaffected.

Every connection to our platforms runs over HTTPS; there is no unencrypted access path. Video consultations use WebRTC, where audio and video are transported over DTLS-SRTP — WebRTC does not permit unencrypted media transport.

Yes. As a video service provider we furnish the proof required by § 2 and § 2a of Anlage 31b BMV-Ä: an information security certificate from a body accredited under ISO/IEC 17065 for the technical procedures under § 365 (1) SGB V, a data protection certificate under Art. 42 GDPR, and a self-declaration on the content requirements. Eight of the platforms we operate are listed in the KBV register.

The controller is XPERTyme GmbH, Starnberger Feldweg 3, 82234 Wessling. Requests under Art. 15 to 21 GDPR go there in writing. Our external data protection officer is Dominik Fünkner, PROLIANCE GmbH, Leopoldstraße 21, 80802 Munich. The competent supervisory authority is the Bayerisches Landesamt für Datenschutzaufsicht in Ansbach.

Who to talk to

Controller

XPERTyme GmbH, Starnberger Feldweg 3, 82234 Wessling, Germany. Requests under Art. 15 to 21 GDPR go there in writing.

Data protection officer

Our external data protection officer: Dominik Fünkner, PROLIANCE GmbH, Leopoldstraße 21, 80802 Munich.

Supervisory authority

Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach.

Your rights

Access, rectification, erasure, restriction of processing, portability and objection under Art. 15 to 21 GDPR.

Need this for a procurement process?

We supply the certificates, the data processing agreement and the technical documentation on request.