Serendipity Health
LEGAL

Privacy Policy

Last updated: 3 October 2026

Protecting your personal data is important to us. This Privacy Policy explains which personal data we process when you use our website and services, the purposes for which such data is processed, and the rights you have under applicable data protection law.

1. Data Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

Tino Schaumlöffel
Physiotherapy Practice / SERENDIPITY HEALTH
Emilienstraße 21
66424 Homburg
Germany

Email: info@serendipityhealth.de
Website: serendipityhealth.de

We are not required to appoint a data protection officer.

2. Legal Bases for Data Processing

We process personal data only in accordance with applicable data protection laws.

Where processing is necessary for the performance of a contract or in order to take steps at your request prior to entering into a contract, processing is carried out on the basis of Article 6(1)(b) GDPR.

Where we are legally required to process or retain certain information, processing is carried out on the basis of Article 6(1)(c) GDPR.

Where processing is based on your consent, the legal basis is Article 6(1)(a) GDPR.

Health data constitutes a special category of personal data under Article 9 GDPR.

Where the processing of health data is necessary in connection with physiotherapy, healthcare or treatment, processing may in particular be based on Article 9(2)(h) GDPR in conjunction with Section 22(1)(1)(b) of the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG).

Where explicit consent is required for the processing of health data, such processing is based on Article 9(2)(a) GDPR.

3. Website Provision and Hosting

This website is hosted by:

INWX GmbH & Co. KG
Prinzessinnenstraße 30
10969 Berlin
Germany

When you access our website, technically necessary information may be processed automatically. This may include, in particular:

  • IP address
  • date and time of access
  • pages or files accessed
  • browser type and browser version
  • operating system
  • referring website
  • technical connection and server information

The processing is necessary to provide the website, ensure its stability and security, detect technical errors and prevent or investigate misuse.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of our website.

All fonts used on this website are hosted locally on our server. No connection to external font services (such as Google Fonts) is established.

4. SSL / TLS Encryption

This website uses SSL/TLS encryption to protect information transmitted between your browser and our server against unauthorised access.

You can recognise an encrypted connection by “https” in your browser’s address bar.

5. Contact by Email

If you contact us by email, we process the information you provide to us. This may include:

  • your name
  • your email address
  • the content of your message
  • other information voluntarily provided by you

Our email service is provided by INWX GmbH & Co. KG, Prinzessinnenstraße 30, 10969 Berlin, Germany, acting as our processor.

Where your contact relates to a requested service, the preparation of a contract or an existing contractual relationship, processing is based on Article 6(1)(b) GDPR. For other enquiries, processing may be based on Article 6(1)(f) GDPR. Our legitimate interest lies in processing and responding to your enquiry.

Please note that standard email is not end-to-end encrypted. We therefore ask you not to send health information by email, but to use the secure questionnaire described in section 7.

If your message nevertheless contains health-related information, the additional provisions set out under “Questionnaires and Processing of Health Data” apply.

6. Booking and Provision of Our Services

If you purchase, request or use one of our services, we process the data required to prepare, perform and administer the respective contractual relationship. This may include:

  • name
  • contact information
  • booked service
  • billing information
  • payment-related information
  • communication data
  • information relating to the provision of the service

Processing is carried out on the basis of Article 6(1)(b) GDPR. Where certain documents or information must be retained due to statutory accounting, tax or other legal obligations, processing is carried out on the basis of Article 6(1)(c) GDPR.

If you use our online withdrawal function, we process the information you enter (name, email address, contract details, message) together with the date and time of receipt in order to process your withdrawal and to send you a confirmation of receipt. The legal basis is Article 6(1)(c) GDPR in conjunction with Section 356a BGB.

7. Questionnaires and Processing of Health Data

As part of our screenings, questionnaires, physiotherapy services, individual training plans and personalised support services, we may process health data. Such information may include, in particular:

  • pain and symptoms
  • injuries
  • illnesses
  • diagnoses
  • previous or planned surgeries
  • medical history
  • previous treatments
  • medication
  • physical limitations
  • mobility
  • physical capacity
  • training status
  • health-related goals
  • movement-related goals

This information is used to assess your individual situation professionally and to prepare, provide and adjust the service you have requested or purchased.

Completed questionnaires and health-related documents are submitted via the secure online forms of our practice management software Cliniko (see section 9).

Providing this information is not legally required. However, without the questionnaire we cannot carry out the screening or provide a personalised programme.

Where the processing is necessary in connection with physiotherapy, healthcare or treatment, the processing is carried out in particular on the basis of Article 9(2)(h) GDPR in conjunction with Section 22(1)(1)(b) BDSG. Where additional processing is based on your explicit consent, Article 9(2)(a) GDPR serves as the legal basis.

Health data is only processed by persons who require access to such information for the provision of your service and who are subject to appropriate confidentiality obligations.

Your health data is not used for advertising or marketing purposes. In particular, health data is not transmitted to Stripe as payment information, payment descriptions or payment metadata.

Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. Withdrawal of consent does not affect processing that is required under statutory retention obligations or that is based on another legal basis.

8. Payment Processing via Stripe

We use Stripe for payment processing. For customers in the European Economic Area, payments are processed by:

Stripe Payments Europe, Limited
One Wilton Park, Wilton Place
Dublin 2, D02 FX04
Ireland

During payment processing, Stripe may process information including:

  • your name
  • email address
  • billing information
  • payment amount
  • purchased service
  • payment information
  • IP address
  • information relating to the selected payment method

Processing is carried out for the purpose of completing and administering the requested payment and is based on Article 6(1)(b) GDPR.

Where Stripe processes personal data for its own legal obligations, including fraud prevention, payment security, anti-money laundering requirements or other regulatory obligations, Stripe may act as an independent data controller for such processing.

Stripe may use other companies and service providers in connection with its services. This may involve the processing of personal data outside the European Economic Area. Where personal data is transferred internationally, Stripe states that it uses appropriate transfer mechanisms where required, including the EU-US Data Privacy Framework and/or European Commission Standard Contractual Clauses.

Further information can be found in Stripe’s own privacy documentation.

9. Cliniko – Practice Management, Online Forms and Video Consultations

For appointment management, secure online forms (including our screening questionnaire) and video consultations, we use the practice management software Cliniko, provided by:

Red Guava Pty Ltd (ACN 147 311 466)
Australia
Privacy policy: cliniko.com/policies/privacy

In this context, the following information may be processed:

  • name and contact details
  • appointment information
  • questionnaire responses and health-related information
  • technical connection information
  • information communicated during the consultation

For accounts created in Europe, Cliniko stores data in Ireland (EU). As Red Guava is based in Australia, access to data from outside the EEA cannot be excluded. Cliniko processes data on our behalf under a data processing agreement pursuant to Article 28 GDPR, which includes European Commission Standard Contractual Clauses for transfers outside the EEA.

Video and audio consultations are not recorded unless this has been expressly agreed in advance and, where required, appropriate consent has been obtained.

The applicable legal basis depends on the purpose of the processing and corresponds to the legal bases described above regarding contractual performance and the processing of health data.

10. Cookies, Analytics and Marketing Technologies

SERENDIPITY HEALTH is designed with data protection in mind. We do not use cookies, analytics, profiling or marketing technologies on this website.

This does not affect technically necessary processing required for the secure operation, functionality and display of the website.

If we introduce analytics, marketing technologies or other technologies requiring consent in the future, this Privacy Policy will be updated accordingly. Where legally required, your consent will be obtained before such technologies are used.

11. Recipients of Personal Data

We only disclose personal data where:

  • disclosure is necessary for the provision of our services,
  • we are legally required to do so,
  • you have consented to the disclosure,
  • or another lawful basis permits the disclosure.

Recipients may include, in particular:

  • hosting and email provider (INWX)
  • practice management and video software (Cliniko)
  • payment service provider (Stripe)
  • tax advisers
  • accounting service providers
  • other service providers necessary for the operation and administration of our services

Where service providers process personal data solely on our behalf, they are engaged as processors in accordance with Article 28 GDPR. We do not sell personal data.

12. Transfers to Third Countries

Certain service providers may process personal data outside the European Union or European Economic Area – in particular Cliniko (Australia) and, where applicable, Stripe.

Any such transfer will only take place where the requirements of Articles 44 et seq. GDPR are fulfilled. Depending on the recipient and destination country, appropriate safeguards may include:

  • an adequacy decision by the European Commission
  • participation in the EU-US Data Privacy Framework
  • European Commission Standard Contractual Clauses
  • other legally recognised safeguards

13. Data Retention

We retain personal data only for as long as necessary for the respective processing purpose or for as long as statutory retention obligations apply.

General enquiries will be deleted once they have been fully processed and there is no legal or legitimate reason for further retention.

Contractual, billing and accounting records are retained in accordance with applicable tax, commercial and other statutory retention requirements.

Where information forms part of a medical or treatment record within the meaning of Section 630f of the German Civil Code (Bürgerliches Gesetzbuch – BGB), the statutory retention period is generally ten years after completion of the treatment, unless other legal requirements provide for a different retention period.

After the applicable retention period expires, personal data will be deleted or anonymised unless another legal basis permits or requires further processing.

14. Data Security

We implement appropriate technical and organisational measures to protect personal data against:

  • loss
  • manipulation
  • unauthorised access
  • unauthorised disclosure
  • destruction
  • other unlawful processing

The particular sensitivity of health data is taken into account when determining appropriate security measures. Access to personal data is limited to persons and systems that require such access for the performance of their respective tasks.

15. Your Data Protection Rights

Subject to the applicable legal requirements, you have the following rights:

RIGHT TO OBJECT (Article 21 GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Article 6(1)(e) or (f) GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. To object, simply email info@serendipityhealth.de.

Right of Access

Under Article 15 GDPR, you have the right to request information about the personal data we process concerning you.

Right to Rectification

Under Article 16 GDPR, you have the right to request the correction of inaccurate personal data and the completion of incomplete personal data.

Right to Erasure

Under Article 17 GDPR, you may have the right to request the deletion of your personal data. This right may be restricted where statutory retention obligations or other legal grounds require us to continue storing certain information.

Right to Restriction of Processing

Under Article 18 GDPR, you may have the right to request restriction of the processing of your personal data.

Right to Data Portability

Where the legal requirements are met, you have the right under Article 20 GDPR to receive certain personal data in a structured, commonly used and machine-readable format and to request its transmission to another controller.

To exercise your rights, please contact info@serendipityhealth.de.

16. Withdrawal of Consent

Where personal data is processed on the basis of your consent, you may withdraw that consent at any time with effect for the future, for example by email to info@serendipityhealth.de.

The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. It also does not affect processing that remains necessary or legally permissible on another legal basis, including statutory retention obligations.

17. Right to Lodge a Complaint

Under Article 77 GDPR, you have the right to lodge a complaint with a competent data protection supervisory authority if you believe that the processing of your personal data violates applicable data protection law. For businesses established in Saarland, the competent supervisory authority is in particular:

Independent Data Protection Centre Saarland
(Unabhängiges Datenschutzzentrum Saarland)
Fritz-Dobisch-Straße 12
66111 Saarbrücken
Germany

18. Automated Decision-Making

We do not use solely automated decision-making, including profiling, within the meaning of Article 22 GDPR in connection with our services.

Professional assessments, recommendations and decisions relating to physiotherapy, training or individual support are not made solely through automated processing.

19. Changes to this Privacy Policy

We may update this Privacy Policy if:

  • our website changes,
  • our services change,
  • we introduce new service providers,
  • our technical infrastructure changes,
  • or legal requirements change.

The version currently published on this website applies.