Wilhelmshavener Straße 41, 10551 Berlin
Data Protection Notice
Status: August 2026. This English translation is provided for convenience; the German version is authoritative.
Launch notice: German privacy counsel must approve the final legal bases, provider entities, transfer safeguards, and retention periods before production.
Deutsche FassungNecessary authentication and account data only
+49 30 346 55555
1. Controller and contact
The controller is Beratung für Digitalisierung - Kumpan GmbH, Wilhelmshavener Straße 41, 10551 Berlin. Managing Director: Matthias Hoppe. Contact: info@zahn-kumpan.de, +49 30 346 55555. Zahn Kumpan is a brand of this company.
2. Registration and portal account
We process your email address, internal user identifier, authentication and security data, and the profile information you provide. Required and optional fields are identified in the interface.
Account processing is necessary to provide the requested service and take pre-contractual steps under Article 6(1)(b) GDPR. Security and abuse prevention rely on our legitimate interest in secure operation under Article 6(1)(f) GDPR. This notice is information, not consent to optional advertising or analytics.
3. Google authentication
Google authentication requests only OpenID, email, and basic profile information. ZahnKumpan does not request contacts, calendar, advertising, or other Google account data.
We receive a Google subject identifier, verified email, and any available name/profile image solely for authentication and account matching. Google may process data under its own privacy terms when its sign-in service is opened.
4. Apple authentication
Apple authentication requests only the provider identifier, email, and a name when Apple provides it during the initial authorization.
Apple private relay addresses are accepted as the account email. ZahnKumpan does not require the underlying personal address. Outbound domains used for relay delivery must be registered with Apple and authenticated with SPF/DKIM.
5. Processors and recipients
Supabase provides authentication, database, storage, and session services as a processor under Article 28 GDPR. Google and Apple process data for their respective authentication services under their privacy terms.
Consultation requests and optional analytics are separate processing activities with their own notices and controls.
6. International transfers
Processing outside the EU/EEA by Google, Apple, Supabase, or their subprocessors is used only where an adequacy decision or safeguards under Articles 44 et seq. GDPR apply, including Standard Contractual Clauses where required. Providers, subprocessors, contracts, and transfer assessments are documented and reviewed.
7. Retention and deletion
Active account data is retained for the account lifetime. Unconfirmed registrations are deleted after 30 days. Account deletion removes the profile, practice, Practice Check data, and stored profile picture.
Versioned evidence of Terms acceptance and notice delivery is restricted after account deletion and ordinarily retained for no more than 36 months. Longer statutory or legal-claims periods, and records for consultation requests, may apply where legally required.
8. Sessions and optional analytics
Essential session technologies are used for authentication, route protection, and security. Optional analytics or marketing requires a separate choice and is not a condition of registration or portal use.
9. Your rights
Subject to legal conditions, you may request access, correction, deletion, restriction, portability, or object to processing. Optional consent can be withdrawn for the future. Account deletion is available in Practice Profile. You may also complain to a competent supervisory authority, including the Berlin Commissioner for Data Protection and Freedom of Information.