Privacy Policy
Last update: August 5, 2026
Thank you for your interest in the information on our website!
With the help of this Privacy Policy we would like to inform the users of our website about the type, scope and purpose of the personal data processed. Personal data in this context is all information that can be used to personally identify you as a user of our website (theoretically in an alternative way or by linking various data), including your IP address. Information that is stored in cookies is generally not or only in exceptional cases personally identifiable; however, cookies are covered by specific regulations that makes the permissibility of the use of cookies dependent on their purpose to a large extent on the active consent of the user.
In a general section of this Privacy Policy, we provide you with information on data protection, which generally applies to our processing of data, including data collection on our website. In particular, you as a data subject will be informed about the rights to which you are entitled.
The terms used in our Privacy Policy and our data protection practice are based on the provisions of the EU General Data Protection Regulation ("GDPR") and other relevant national legal provisions.
Controller according to the GDPR
Dr. Lorenz Pötz
Linke Wienzeile 46/12
1060 Wien
Austria
e: ordination@drpoetz.at
t: +43 664 3401708
Data Protection Coordinator:
Mr. Dr. med. univ. Lorenz Pötz
Data collection on our website
On the one hand, personal data is collected from you when you expressly communicate such data to us, on the other hand, data, especially technical data, is automatically collected when you visit our website. Some of this data is collected to ensure that our website functions without errors. Other data may be used for analysis purposes. However, you can use our website without a need to provide personal information.
Technologies on our website
Cookies and Local Storage
We use cookies to make our website as user-friendly and functional as possible for you. Some of these cookies are stored on the device you use to access the site.
Cookies are small packages of data that are exchanged between your browser and our web server whenever you visit our website. They do not cause any damage and are used solely to recognise website visitors. Cookies can only store information provided by your browser, e.g. information that you have entered into your browser or that is available on the website. Cookies cannot execute code and cannot be used to access your terminal device.
The next time you access our website using the same device, the information stored in the cookies can then either be sent back to us (“first-party cookie”) or to a web application of third party to whom the cookie belongs (“third-party cookie”). The information that is stored and sent back allows each web application to recognise that you have already accessed and visited the website using the browser on your device.
Cookies contain the following information:
- Cookie name
- Name of the server from which the cookie originates
- Cookie ID number
- An expiry date, after which the cookie will be automatically deleted
We classify cookies in the following categories depending on their purpose and function:
- Technically necessary cookies, to ensure the technical operation and basic functions of our website. These types of cookies are used, for example, to maintain your settings while you navigate our website; or they can ensure that important information is retained throughout the session (e.g. login, shopping cart).
- Statistics cookies, to understand how visitors interact with our website by collecting and analysing information on an anonymous basis only. In this way we gain valuable insights to optimize both the website and our products and services.
- Marketing cookies, to provide targeted promotional and marketing activities for users on our website.
- Unclassified cookies are cookies that we are trying to classify together with individual cookie providers.
Depending on the storage period, we also divide cookies into session and persistent cookies. Session cookies store information that is used during your current browser session. These cookies are automatically deleted when the browser is closed. No information remains on your device. Persistent cookies store information between two visits to the website. Based on this information, you will be recognized as a returning visitor on your next visit and the website will react accordingly. The lifespan of a persistent cookie is determined by the provider of the cookie.
The legal basis for using technically necessary cookies is our legitimate interest in the technically fault-free operation and smooth functionality of our website. The use of statistics and marketing cookies is subject to your consent. These technologies are only activated after you have provided explicit consent via the cookie banner. You can withdraw your consent for the future use of cookies at any time. Your consent is voluntary. If consent is not given, no disadvantages arise. For more information about the cookies we actually use (specifically, their purpose and lifespan), refer to this Privacy Policy and to the information in our cookie banner about the cookies we use.
You can also set your web browser so that it does not store any cookies in general on your device or so that you will be asked each time you visit the site whether you accept the use of cookies. Cookies that have already been stored can be deleted at any time. Refer to the Help section of your browser to learn how to do this.
Please note that a general deactivation of cookies may lead to functional restrictions on our website.
On our website, we also use so-called local storage functions (also called "local data"). This means that data is stored locally in the cache of your browser, which continues to exist and can be read even after you close the browser - as long as you do not delete the cache or data is stored within the session storage.
Third parties cannot access the data stored in the local storage. If special plug-ins or tools use the local storage functions, you are informed within the description of the respective plug-in or tool.
If you do not wish plug-ins or tools to use local storage functions, you can control this in the settings of your respective browser. We would like to point out that this may result in functional restrictions.
Google Fonts
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company Google LLC (USA), https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active
Purpose: Integration of fonts
Category: Statistics
Recipients: EU, USA (possible)
Data processed: IP address, language settings, screen resolution, version and name of browser.
Data subjects: website visitors
Technology: JavaScript call
Legal basis: Consent, Data Privacy Framework
Website: www.google.com
Further information: https://developers.google.com/fonts/faq https://policies.google.com/privacy https://www.google.com/about/datacenters/inside/locations/
To display fonts consistently, our website uses Web Fonts which are provided by Google.
To display web fonts, the web browser you use must connect with a Google server. This informs Google that our website is being accessed via your IP address. The IP address from the browser of the device you are using to access our site is also stored by Google. If your browser does not support Web Fonts, your device will display the site using a standard font type. With each Google Font request, your IP address is automatically transferred to a Google server along with information such as your language preferences, display resolution, version and name of your browser. The usage data collected by Google enables them to determine the popularity of specific font types. Google publishes these findings on internal analytics sites (e.g. Google Analytics).
Google Fonts enables us to use fonts on our own website without uploading them to our server. Google Fonts is an important building block for maintaining the high quality of our website. All Google fonts are automatically optimized for the web. This reduces the data volume and is particularly advantageous for use on mobile devices. When you visit our site, the low file size allows for quicker loading times. Furthermore, Google Fonts are secure Web Fonts that support all major browsers.
Google stores requests for CSS assets for one day on its servers. This enables us to use the fonts with the support of a Google style sheet. The font files are stored by Google for one year. To delete data prematurely, you must contact Google Support ( https://support.google.com ).
Google Maps
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC (USA)
Purpose: Integration of Map Services
Category: Statistics
Recipients: EU, USA
Data processed: IP Address, Website Visit Details, User Data
Data subjects: Users
Technology: JavaScript Call, Cookies
Legal basis: Consent, Data Privacy Framework, https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active
Website: https://www.google.com
Further information:
https://policies.google.com/privacy
https://safety.google/intl/en/principles/
https://business.safety.google/adsprocessorterms/
Here you can find out where exactly Google data centers are located: https://www.google.com/about/datacenters/inside/locations/
On our website, the service Google Maps is integrated in order to better display geographical information about locations for users.
Google Maps is an online map service with which geographic information can be made more legible via a terminal device. Among other things, directions are displayed or map sections of a location can be integrated into a website.
When Google Maps is called up, the browser establishes a connection to Google's servers. This enables Google to know that our website has been accessed via the user's IP address. The use of Google Maps enables Google to collect and process data about the use of the service.
For the provision of this service, Google Maps processes, among other things, entered search terms as well as latitude and longitude coordinates on the basis of the IP address. If the route planner function of Google Maps is used, the entered starting address is also stored. This data processing is carried out exclusively by Google and is not within our sphere of influence.
We would like to point out that a cookie called "NID" is set by Google when running this service. Google Maps does not currently offer us the option to run this service in a mode without this cookie. The NID cookie contains information about your user behavior, which Google uses to optimize its own services and to provide individual, personalized advertising for you.
Google anonymizes data in server logs by deleting a portion of the IP address and cookie information after 9 and 18 months, respectively.
Location and activity data is stored for either 3 or 18 months and then deleted. Users can also manually clear history at any time via a Google account. To completely prevent location tracking, a user must turn off the "Web and App Activity" section in their Google account.
Google Ad Manager (formerly DoubleClick for Publishers + DoubleClick Ad Exchange)
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Parent Company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Purpose: Management, marketing, and display of advertising space on our website, including programmatic ad sales (real-time bidding) across multiple ad networks and exchanges
Recipients: EU, USA, and, where applicable, other third-party providers involved in the bidding process (demand-side platforms, ad networks)
Category: Marketing
Data processed: IP address (briefly for approximate location determination), cookie/device ID, information on page content and ad placements viewed, technical device information (browser, screen resolution)
Data subjects: Website visitors
Technology: JavaScript (Google Publisher Tag / gpt.js), cookies, and, if applicable, additional header bidding scripts from other providers participating in the bidding process
Legal basis: Consent
Legal basis for data transfer: Data Privacy Framework (Google LLC); for participating third-party providers without their own DPF certification, Standard Contractual Clauses (SCCs) apply
Website: https://www.google.com
Further information:
https://policies.google.com/privacy
https://safety.google/intl/de/principles/
https://business.safety.google/privacy/
https://business.safety.google/adsprocessorterms/
https://policies.google.com/technologies/ads
https://www.google.com/about/company/user-consent-policy-help
Here you can find out exactly where Google’s data centers are located: https://www.google.com/about/datacenters/inside/locations/
This website uses the Google Ad Manager service to market and display our ad spaces. When a page containing an ad space is loaded, the browser sends a request to the Google ad server, whereupon the gpt.js script generates an ad request and forwards it to the server. The ad server checks the transmitted target values for the ad space (size, position, and, if applicable, targeting criteria) and delivers the appropriate ad. If ad spaces are sold programmatically via real-time bidding, multiple ad exchanges and third-party providers may participate in the auction simultaneously and process data in the process. In this case, granular consent is required that covers the individual providers involved, not just a blanket entry for “Google.”
Google Tag Manager
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company: Google LLC (USA)
Purpose: Launching Tools and Plugins
Category: Technically Required
Recipients: EU, USA (possible)
Data processed: IP Address
Data subjects: User
Technology: JavaScript Call
Legal basis: legitimate interest, Data Privacy Framework, https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active
Website: https://www.google.com
Further information:
https://policies.google.com/privacy
https://safety.google/intl/en/principles/
https://business.safety.google/adsprocessorterms/
Here you can find out where exactly Google data centers are located: https://www.google.com/about/datacenters/locations/
The Google Tag Manager service is used on our website.
The Tag Manager is a service that allows us to manage website tags via an interface. This allows us to include code snippets such as tracking codes or conversion pixels on websites without interfering with the source code. In doing so, the data is only forwarded by the Tag Manager, but neither collected nor stored. The Tag Manager itself is a cookie-less domain and serves purely to manage other services in our online offering.
When the Google Tag Manager is started, the browser establishes a connection to Google's servers. These are mainly located in the U.S. Through this, Google obtains knowledge that our website was called up via the IP address of a user.
The Tag Manager ensures the resolution of other tags, which in turn may collect data. However, the Tag Manager does not access this data. If a deactivation has been made at the domain or cookie level, this remains in place for all tracking tags that are implemented with the Tag Manager.
SSL Encryption
Within your visit to our website, we use the widespread SSL procedure (Secure Socket Layer) in conjunction with the highest level of encryption supported by your browser. You can tell whether an individual page of our website is transmitted in encrypted form by the closed representation of the key or lock symbol in the lower status bar of your browser. We use this encryption procedure on the basis of our justified interest in the use of suitable encryption techniques.
We also make use of suitable technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorised access by third parties. Our security measures are continuously improved in line with technological developments and kept state-of-the-art.
Webcare
Provider: DataReporter GmbH, Zeileisstraße 6, 4600 Wels, Austria.
Purpose: Consent Management
Category: technically required
Recipient: EU, AT
Data processed: IP Address, Consent Data
Data subjects: Users
Technology: JavaScript call, Cookies, Swarmcrawler
Legal basis: Legitimate interest, consent (swarmcrawler to evaluate search results)
Website: https://www.datareporter.eu/
Further information: https://www.datareporter.eu/company/info
On our website, we use the Webcare tool for consent management. Webcare records and stores the decision of each user of our website. Our Consent Banner ensures that statistical and marketing technologies such as cookies or external tools are only set or started if the user has expressly consented to their use.
We store information on the extent to which the user has confirmed the use of cookies. The user's decision can be revoked at any time by accessing the cookie setting and managing the declaration of consent. Existing cookies are deleted after revocation of consent. For the storage of information about the status of the consent of the user, a cookie is also set, which is referred to in the cookie details. Furthermore, the IP address of the respective user(s) is transmitted to DataReporter's servers when this service is called up. The IP address is neither stored nor associated with any other data of the user, it is only used for the correct execution of the service.
With the help of Webcare, our website is regularly checked for technologies relevant to data protection. This investigation is only carried out for those users who have expressly given their consent (for statistical or marketing purposes). The search results of the users are evaluated by Webcare in an anonymous form and only in relation to technologies and used for the fulfillment of our information obligations. To start the Swarmcrawler technology, a request is sent to our servers and the IP address of the user is transmitted for the purpose of data transfer. Servers are selected which are geographically close to the respective location of the user. It can be assumed that for users within the EU, a server with a location within the EU will also be selected. The IP address of the user is not stored and is removed immediately after the end of the communication.
Google Analytics
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Email: support-de@google.com
Parent Company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Purpose: Web analytics, performance measurement, conversion tracking, collection of statistical data
Category: Statistics
Recipients: EU, USA
Data Processed: Information about website visits (see detailed list below), user data. The IP address is used only briefly for rough location determination and is not stored afterward (see below).
Data Subjects: Website visitors
Technology: JavaScript call (Google tag / gtag.js), cookies (details in the cookie list), local storage
Legal basis: Consent
Legal basis for data transfer: EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework
Further information:
https://policies.google.com/privacy
https://safety.google/intl/de/principles/
https://business.safety.google/privacy/
https://business.safety.google/adsprocessorterms/
https://policies.google.com/technologies/ads
https://www.google.com/about/company/user-consent-policy-help
Here you can find out exactly where Google data centers are located: https://www.google.com/about/datacenters/locations/
Web and app activities collected via Google Analytics can be viewed and deleted by signed-in Google users under “My Activity” (myaccount.google.com/data-and-privacy).
On our website, we use the features of the web analytics service Google Analytics 4 (GA4) to analyze user behavior and optimize our website.
Google Analytics uses cookies that enable the analysis of our website’s usage. Full details (name, purpose, retention period) regarding these cookies can be found in our specific list of cookies used. As an alternative to cookies, GA4 may use local storage to store the client ID in order to track user behavior even without a traditional cookie.
Information about website usage—such as browser type and version, operating system used, the previously visited page, the time of the server request, and approximate location—is transmitted to Google and processed there. We have entered into a contract with Google for this purpose.
With regard to IP addresses, there is no traditional “anonymization” in the sense of truncation after transmission; rather, GA4 is designed from the ground up so that IP addresses are neither logged nor stored for visitors from the EU, Switzerland, and the UK. The IP address is used only briefly to determine a rough location (city, region, country) and is then irrevocably discarded before it is stored on Google’s servers. This is a feature built into GA4 that cannot be disabled; it is not an optional setting.
On our behalf, Google will use this information to analyze the use of our website, compile reports on activity on our website, and provide us with other services related to the use of our website.
During a visit to the website, user behavior is recorded in the form of so-called events. These may include the following:
- Page views, a user’s click path
- First-time visit to our website
- Websites visited
- Start of a session
- Interaction with our website
- User behavior (e.g., clicks, scrolling, time spent on page, bounce rates)
- File downloads
- Ads viewed/clicked (only if Google Ads is linked to this property and Google Signals is enabled)
- Interaction with videos
- Internal search queries
The following is also collected:
- Approximate location (region, derived from the IP address, without storing the IP address itself)
- Date and time of the visit
- Technical information about the browser or the devices used (e.g., language setting, screen resolution)
- Internet service provider
- Referrer URL (the website or advertising channel through which a user arrived at our website)
This data is primarily processed by Google for its own purposes, such as profiling (over which we have no control).
Data regarding the use of our website is deleted immediately upon expiration of the retention period we have set. By default, Google Analytics specifies a retention period of 2 months for user and event data, with a maximum retention period of 14 months. This retention period also applies to conversion data. For all other event data, the following options are available: 2 months, 14 months, 26 months (Google Analytics 360 only), 38 months (Google Analytics 360 only), 50 months (Google Analytics 360 only). We select the shortest retention period that meets our intended purpose. You may inquire with us at any time regarding the retention period currently set by us. Data for which the retention period has expired is automatically deleted once a month.
Additional details can be found in the linked supplementary information. We recommend checking these links regularly for changes, as Google Analytics may update its features and privacy policies. Further information regarding your rights and our contact information can be found in the general section of this privacy policy.
Bot and attack protection
Category: General processing activity
Purpose: Detection, defense, and analysis of automated access and potential attacks
Data types: IP addresses, device and browser data, technical event and access patterns
Data subjects: Website users
Recipients: Security service providers (in the case of external processing)
Technologies: Bot detection, traffic scanning, anomaly analysis
Legal basis: Legitimate interest (security, stability, and protection of systems)
Our website may use services that detect automated access, bots, or potential attacks. These systems analyze technical information to identify and defend against unusual patterns, suspicious activity, or known attack signatures. They work in the background and contribute to the security and stability of our online offering.
Depending on the service used, the following types of data in particular may be processed:
- IP address
- Browser and device information
- Technical connection data
- Access times
- Request and server information
- Anomalies in access patterns
- Information about automated or suspicious activities
- Data from security checks or filter mechanisms
Processing is carried out to prevent unauthorized access, ward off attacks (e.g., DDoS, automated scans, or brute force attempts), and ensure the proper functioning of the online offering. External service providers may process technical data as part of their protection mechanisms, for example to detect attacks, ensure stability, or prevent misuse.
The legal basis for processing is our legitimate interest in a secure, stable, and functional online offering. Consent is not required for this, as this processing is technically necessary to ensure the security of the website.
The data is only stored for as long as is necessary for security purposes or as required by legal or technical requirements. Data is only passed on to other third parties if this is necessary to defend against attacks, for technical provision, or due to legal obligations.
Direct contact
Category: General processing activity
Purpose: Communication and processing of inquiries
Data types: Communication and content data, technical metadata
Data subjects: Person making contact
Recipients: Internal departments, email providers
Technologies: Email communication
Legal basis: Legitimate interest (general communication), contract fulfillment (for service-related inquiries)
If direct contact is made via the communication channels provided, we process the information transmitted in order to receive, process, and respond to the request. Depending on the communication channel used, the following data in particular may be processed:
- Email address or other contact details
- Name or identification data (if provided)
- Content of the message or inquiry
- Other voluntary information
- Technical metadata of the respective communication service (e.g., timestamp, server data, transmission information)
The processing is carried out to respond to the request and for communication purposes. The legal basis is our legitimate interest in an efficient, reliable, and user-friendly means of contact and—if the inquiry is aimed at initiating or executing a contract—the necessity of processing for this contractual relationship.
The data is only stored for as long as is necessary to process the request or as long as there are legal retention obligations. The data is not passed on to third parties unless this is necessary for processing the request or results from the communication channel used.
External resources
Category: General processing activity
Purpose: Presentation, functionality, and technical provision
Data types: Technical data
Data subjects: Visitors to the online offering
Recipients: Providers of the integrated resources
Technologies: External scripts, fonts, or frameworks
Legal basis: Legitimate interest (presentation & function)
External resources from third-party providers are integrated for the presentation and functionality of our online offering. When this content is loaded, a connection to the servers of the respective provider is established. Technical information may be transferred and processed, including:
- IP address
- Date and time of access
- Resource accessed
- Browser type and browser version
- Operating system used
- Referrer URL
The integration of such external resources serves to ensure a uniform presentation of the website, an improved user experience, and the technical and functional provision of our online offering. The legal basis for the processing is our legitimate interest in a user-friendly, secure, and efficient presentation of the website.
The data is processed by the respective provider of the integrated resource. Where possible, we integrate external content in a data-efficient manner or use alternatives that reduce data transmission.
Hosting
In the context of hosting our website, all data that arises in connection with the operation and use of the website is processed. This includes, in particular, content data, usage data, communication data, and technical data that are necessary for providing and securely operating the website.
The storage and processing of this data is necessary to enable access to the website, ensure the stability and security of the online offering, and to technically optimize the website.
To provide our online presence, we use the services of external web hosting providers. In this context, the data generated during the operation of the website is transmitted to these service providers or processed by them on our behalf. Processing is carried out exclusively in accordance with legal requirements and based on contractual agreements for data processing on behalf.
Further information on the handling of personal data in connection with hosting can be found in the privacy policy of this website.
Map services
Category: General processing activity
Purpose: Display of location or map information
Data types: Technical data and location-related retrieval data
Data subjects: Visitors to the online offering
Recipients: Map service providers
Technologies: Map API or embedding
Legal basis: Legitimate interest (presentation & function)
Map services are integrated into our website to display geographical information, locations, or routes. When a page with such a service is accessed, a connection to the servers of the respective provider is established. The technical information required for the provision of the map is processed in the process. This may include, in particular:
- IP address
- Date and time of access
- Page or map section accessed
- Browser type and browser version
- Operating system used
- Referrer URL
- Server and device information
The processing is carried out in order to provide the map functions, optimize the display, and ensure the technical security of the service. The map provider may also process the transmitted data for its own purposes, for example to improve the service or for security analyses. The legal basis is our legitimate interest in a user-friendly and functional display of location and map information.
The data is only stored for as long as is necessary to provide the map functions or to ensure technical functionality. It is only passed on to other third parties if this is necessary for the technical operation of the map service.
Usage behavior tracking
Category: General processing activity, marketing
Purpose: Evaluation of individual usage patterns
Data types: Interaction, movement, and usage data
Data subjects: Visitors to the online offering
Recipients: Tracking service providers
Technologies: Behavior and interaction analysis
Legal basis: Consent
Our website uses technologies that record the behavior of individual users in detail. These services analyze interactions such as clicks or the use of individual page areas. They are only activated if explicit consent has been given beforehand. No tracking takes place without consent.
If consent is given, various personal and technical information may be processed depending on the service. This may include, in particular:
- Click behavior and interactions
- Scroll depth and movement patterns
- Use of individual elements or page sections
- Session recordings or heat maps
- Technical data such as IP address (truncated if necessary), time of visit, browser and device information
Referrer URL
Processing is carried out in order to understand the behavior of individual users, improve the functionality of the website, optimize user paths, and identify possible technical problems. Cookies, tracking scripts, or similar technologies may be used. If external service providers are used, the collected data may be transferred to them and processed there. The legal basis is the consent given in advance, which can be revoked at any time with effect for the future. Corresponding revocation options are available within our online offering or via the settings provided.
The data will only be stored for as long as is necessary for the analysis or until consent is revoked. Data will only be passed on to other third parties within the scope of the technical provision of the respective tracking service.
Online appointments
Category: General processing activity
Purpose: Planning and management of appointments
Data types: Contact, appointment, and content data
Data subjects: Appointment bookers
Recipients: Internal departments, appointment booking service providers
Technologies: Appointment booking system
Legal basis: Contract fulfillment (appointment-related processes), legitimate interest (organization & communication), consent (voluntary additional information)
An online appointment booking service is available on our website. The data entered during this process is processed in order to plan and coordinate appointments and to send confirmations or feedback. In addition, technical transmission data is collected that is necessary for the secure operation and assignment of the request.
In particular, the following data is processed:
- Name
- Contact details
- Desired appointment
- Information about the reason for or content of the appointment
- Other voluntary information
- Technical metadata such as time of transmission or IP address
The processing is carried out in order to receive appointment requests, coordinate appointments, clarify queries, and send confirmations or reminders. If an external service provider is used for appointment booking, the data entered is transmitted to this service provider and processed there. The legal basis is our legitimate interest in efficient appointment management and the necessity of processing for the preparation or execution of a contractual relationship, provided that the appointment is related to this. Voluntary additional information is processed on the basis of consent.
The data will only be stored for as long as is necessary for the organization and execution of the appointment or as long as there are legal retention obligations. Data will only be passed on to third parties if this is necessary for appointment management or the technical provision of the booking system.
Server-Logfiles
Category: General processing activity
Purpose: Technical security, stability, and error analysis
Data types: Technical connection data and access data
Data subjects: Visitors to the online offering
Recipients: Hosting providers or technical service providers
Technologies: Server logs
Legal basis: Legitimate interest (technical operation & security)
When you visit our website, so-called server log files are automatically created. These log files contain the following data, which is automatically transmitted by the browser:
- IP address
- Date and time of access
- File or page accessed
- Amount of data transferred
- Notification of successful retrieval
- Browser type and version used
- Operating system used
- Referrer URL (previously visited page)
- Host name of the accessing device
This data is processed to ensure the functionality, security, and stability of our website, in particular to defend against or track attacks (e.g., DDoS attacks), for error analysis, and for the technical provision of the website. The legal basis for this is a legitimate interest in the secure and error-free provision of the website.
The log file data is automatically deleted after a standard technical period – after 12 weeks at the latest– once it is no longer required for the aforementioned purposes. Longer storage may occur in individual cases if data is required for evidence purposes (e.g., to investigate security-related incidents). This data is not merged with other data sources.
Security or protection services
Category: General processing activity
Purpose: Ensuring technical stability, protection against attacks, failures, and manipulation
Data types: Access data, IP addresses, device and browser information, technical event data
Data subjects: Website users
Recipients: Providers of the respective security service
Technologies: Firewall systems, security monitoring, infrastructure protection mechanisms
Legal basis: Legitimate interest (protection and operational security of the website)
Security and protection services may be used on our website to ensure technical operation, detect attacks, and prevent abusive activities. Such services analyze technical information to identify anomalies, manipulation attempts, or security risks and implement appropriate protective measures.
In particular, the following types of data are processed:
- IP address
- Browser and device information
- Technical connection data
- Access times
- Request and server information
- Information about suspicious or unusual activities
- Data from security-related checks or filter mechanisms
Processing is necessary to prevent unauthorized access, ensure system stability, prevent manipulation and malware, and guarantee the secure operation of the website. If external security service providers are used, they may receive the necessary data and process it in their own infrastructure.
The legal basis for processing is our legitimate interest in the protected, trouble-free, and technically reliable provision of our online services. The data is only stored for as long as is necessary to ensure security and fault tolerance or as required by law. Data is only passed on to third parties within the technical framework of the security service used.
Web analysis
Category: General processing activity, statistics
Purpose: Usage analysis and optimization of the website
Types of data: Technical usage data, interaction data, device information
Data subjects: Visitors to the online offering
Recipients: Analysis service providers
Technologies: Analysis and measurement functions
Legal basis: Consent
Our website uses web analysis methods that record general visitor and usage behavior in anonymized or pseudonymized form. The information processed in this way is used for statistical evaluation of page views, to determine usage figures, and to optimize the technology and content of our online offering. In addition, technical access data is processed to provide analysis functions and ensure system stability.
The following data in particular is processed:
- IP address or a shortened IP address
- Date and time of the page view
- Pages viewed
- Length of stay
- Internal navigation
- Browser and device information
- Referrer URL
- Technical usage and interaction data
Cookies or similar technologies may be used to recognize repeat visits or to assign usage processes. If external analysis providers are used, the collected data may be transmitted to them and processed there. The legal basis is voluntary consent, which can be revoked at any time with effect for the future. Corresponding adjustment options are available within our online offering or via the revocation functions provided.
The data is only stored for as long as is necessary for statistical evaluations or until consent is revoked. Data is only passed on to other third parties within the scope of the technical provision of the respective analysis service.
General information on data protection
The following provisions in its principles apply not only to the data collection on our website, but also in general to other processing of personal data.
Personal data
Personal data is information that can be assigned to you individually. Examples include your address, your name as well as your postal address, email address or telephone number. Information such as the number of users who visit a website is not personal data because it is not assigned to a person.
Legal basis for the processing of personal data
Unless more specific information is provided in this Privacy Policy (e.g. in the case of the technologies used), we may process personal data from you on the basis of the following legal principles:
- consent in accordance with Art. 6 paragraph 1 lit. a of the GDPR - The data subject has given his or her consent to the processing of his or her personal data for one or more specific purposes.
- Fulfillment of a contract and pre-contractual measures pursuant to Art. 6 paragraph 1 lit. b of the GDPR - Processing is necessary for the fulfillment of a contract to which the data subject is a party or for the implementation of pre-contractual measures.
- Legal obligation pursuant to Art. 6 paragraph 1 lit. c of the GDPR - Processing is necessary for the performance of a legal obligation.
- Protection of vital interests pursuant to Art. 6 paragraph 1 lit. d of the GDPR - Processing is necessary to protect the vital interests of the data subject or of another natural person.
- Reasonable interests pursuant to Art. 6 paragraph 1 lit. f of the GDPR - The processing is necessary to protect the legitimate interests of the controller or of a third party unless the interests or fundamental rights and freedoms of the data subject prevail.
Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our home country.
Transfer of personal data
Your personal data will not be transferred to third parties for purposes other than those listed in this Privacy Policy.
We will only transfer your personal data to third parties if:
- you have given your express consent in accordance with Art. 6 paragraph 1 lit. a of the GDPR,
- the transfer pursuant to Art. 6 paragraph 1 lit. f of the GDPR is necessary to safeguard reasonable interests, as well as to assert, exercise or defend legal claims and there is no reason to assume that you have a prevailing interest worthy of protection by not disclosing your data,
- there is a legal obligation to transfer the data in accordance with Art. 6 paragraph 1 lit. c of the GDPR, as well as this is legally permissible and / or
- it is required according to Art. 6 paragraph 1 lit. b of the GDPR for the processing of contractual relationships with you.
Cooperation with processors
We carefully select our service providers who process personal data on our behalf. If we commission third parties to process personal data on the basis of a data processing agreement, this is done in accordance with Art. 28 of the GDPR.
Transfer to third countries
If we process data to a third country or if this is done in the context of using the services of third parties or disclosure or transfer of data to other persons or companies, this is only done on the legal basis described above for the transfer of data.
Subject to express consent or contractual necessity, we process or allow data to be processed only in third countries in accordance with Art. 44 - 49 of the GDPR with a recognized level of data protection or on the basis of special guarantees, such as contractual obligations through so-called standard contractual clauses of the EU Commission, the existence of certifications or binding corporate rules.
Data transfer to the U.S.
We would like to explicitly point out that as of July 10, 2023, the EU Commission has issued an adequacy decision on the EU-US data protection framework (Data Privacy Framework) pursuant to Art. 45 paragraph 1 GDPR. Accordingly, organizations or companies (as data importers) in the US that are registered in a public list as part of the self-certification of the Data Privacy Framework provide an adequate level of protection for data transfers. Whether the specific provider of a service is already certified can be found here: https://www.dataprivacyframework.gov/s/participant-search
The Data Privacy Framework provides a valid legal basis for the transfer of personal data to the USA. This creates binding guarantees to comply with all ECJ requirements; for example, it provides that access by U.S. intelligence services to EU data is limited to a necessary and proportionate level and that a data protection review court is created to which individuals in the EU also have access.
If a transfer of data by us to the US takes place at all or if a service provider based in the US is used by us, we refer to this explicitly in this Privacy Policy (see in particular the description of the technologies used on our website).
It should be noted that aside from significant improvements, the Data Privacy Framework is only partial and only applies to data transfers to those data importers in the U.S. that appear on the public list of certified organizations/companies.
What can the transfer of personal data to the US mean for you as a user and what risks are involved?
Risks for you as a user as far as data importers in the USA are concerned, which are not covered by the Data Privacy Framework, are in any case the powers of the US secret services and the legal situation in the U.S., which currently, according to the European Court of Justice, no longer ensure an adequate level of data protection. Among others, these are the following:
- Section 702 of the Foreign Intelligence Surveillance Act (FISA) does not provide for any restrictions on the surveillance measures of the secret services or guarantees for non-US citizens.
- Presidential Policy Directive 28 (PPD-28) does not provide effective remedies for those affected against actions by U.S. authorities and does not provide barriers to ensuring proportionate measures.
- The ombudsman provided for in the Privacy Shield does not have sufficient independence from the executive; he cannot issue binding orders to the U.S. secret services.
Legally compliant transfer of data to the U.S. on the basis of the standard contractual clauses for data importers not covered by the Data Privacy Framework?
In June 2021, the European Commission adopted new Standard Contractual Clauses (SCC) in Decision 2021/914/EU. These create a new legal basis for data transfers where the level of data protection is not the same as in the EU.
Legally compliant transfer of data to the U.S. based on consent?
If a data transfer to a service provider based in the U.S. takes place that is not covered by the Data Privacy Framework and this data transfer is based on explicit consent, we provide explicit information about this in this privacy policy, in particular in the description of the technologies used on our website.
What measures do we take to ensure that data transfers to the U.S. are legally compliant?
Where US providers offer the option, we choose to process data on EU servers. This should technically ensure that the data is located within the European Union and that access by US authorities is not possible.
Storage periods in general
If no explicit storage period is specified during the collection of data (e.g. in the context of a declaration of consent), we are obliged to delete personal data in accordance with Art. 5 paragraph 1 lit. e of the GDPR as soon as the purpose for processing has been fulfilled. In this context, we would like to point out that legal storage obligations represent a legitimate purpose for the further processing of affected personal data.
Personal data will be stored and retained by us in principle until the termination of a business relationship or until the expiry of any applicable guarantee, warranty or limitation periods, in addition, until the end of any legal disputes in which the data is required as evidence, or in any event until the expiry of the third year following the last contact with a business partner.
Storage periods in particular
As part of the description of individual technologies on our website, there are specific references to the storage period of data. In our cookie table, you will be informed about the storage period of individual cookies. In addition, you always have the possibility to ask us directly about the specific storage period of data. To do so, please use the contact data listed in this Privacy Policy.
Rights of data subjects
Data subject have the right:
- (i) in accordance with Art. 15 of the GDPR, to request information about your personal data processed by us. In particular, you may request information on the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned duration of storage, the existence of a right of rectification, deletion, restriction of processing or opposition, the existence of a right of appeal, the origin of your data, if not collected by us, as well as the existence of automated decision making including profiling and, where applicable, meaningful information on the details thereof;
- (ii) in accordance with Art. 16 of the GDPR, to demand without delay the correction of incorrect or incomplete personal data stored by us;
- (iii) in accordance with Art. 17 of the GDPR, under specific circumstances to demand the deletion of your personal data stored with us, unless the processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims;
- (iv) in accordance with Art. 18 of the GDPR, to demand the (temporary) restriction of the processing of your personal data, insofar as the accuracy of the data is disputed by you, the processing is unlawful, but you refuse to delete it and we no longer require the data, but you require it for the assertion, exercise or defense of legal claims or you have lodged an objection to the processing in accordance with Art. 21 of the GDPR;
- (v) in accordance with Art. 20 of the GDPR, to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request that it be transferred to another controller; However, this only covers those of your personal data that we process with the help of automated processes after your consent or on the basis of a contract with you;
- (vi) in accordance with Art. 21 of the GDPR, if your personal data are processed on the basis of our legitimate interest, to object to the processing of your personal data for reasons arising from your specific situation or if the objection is directed against direct advertising. In the latter case, you have a general right of objection, which we will implement without indicating a specific situation.
- (vii) in accordance with Art. 7 paragraph 3 of the GDPR, you may at any time revoke your consent to us. As a result, we may no longer continue the data processing based on this consent in the future. Among other things, you have the option of revoking your consent to the use of cookies on our website with effect for the future by calling up our Cookie Settings.
- (viii) in accordance with Art. 77 of the GDPR to complain to a data protection authority regarding the illegal processing of your data by us. As a rule, you can contact the data protection authority at your usual place of residence or workplace or at the headquarters of our company.
The responsible data protection authority for Dr. Lorenz Pötz is:
Österreichische Datenschutzbehörde
Barichgasse 40-42, 1030 Wien, Österreich
Tel.: +43 1 52 152-0, dsb@dsb.gv.at
Assertion of rights of data subjects
You yourself decide on the use of your personal data. Should you therefore wish to exercise one of your above-mentioned rights towards us, you are welcome to contact us by email at ordination@drpoetz.at or by post, as well as by telephone.
Please assist us in specifying your request by answering questions from our responsible employees regarding the specific processing of your personal data. If there are reasonable doubts about your identity, we may request a copy of your identification.
For questions regarding data protection, you can reach us at ordination@drpoetz.at or at the other contact details stated in this Privacy Policy.
Wien, on August 5, 2026