Privacy policy
This policy describes which personal data we process when you visit medicalexperts.de, for what purpose, on what legal basis and for how long. It also describes which rights you have and how to exercise them.
We use analytics and marketing techniques only with your consent. As long as you have not consented, no Google script is loaded and no analytics cookie is set on this website. You can change your decision at any time:
1. Controller
The controller for the processing of data on this website within the meaning of Art. 4 Nr. 7 DSGVO (Article 4(7) of the Datenschutz-Grundverordnung, DSGVO — the General Data Protection Regulation, GDPR) is:
MEX Agency of Medical Experts GmbH
Burgweg 5a
61389 Schmitten im Taunus
Germany
Represented by the managing directors Jörg Saborowski and Julian Raab
Commercial register: HRB 5004, Amtsgericht Königstein (Königstein Local Court)
Email: [email protected]
Further provider details can be found in the legal notice. For requests for access, erasure or objection, an informal message to the address above is sufficient.
2. Principles
We collect personal data only to the extent necessary to operate the website, to handle your enquiry or to improve our professional content. Personal data means any information relating to an identified or identifiable person — a name, an email address or an IP address, for example.
Transmission between your browser and our server is TLS-encrypted throughout (recognisable by the padlock symbol in your browser). We neither sell nor rent data.
3. Legal bases
We base the individual processing operations on the following:
- Art. 6 Abs. 1 lit. a DSGVO (Article 6(1)(a) GDPR) — your consent, for example for analytics and reach measurement. It is voluntary and can be withdrawn at any time with effect for the future.
- Art. 6 Abs. 1 lit. b DSGVO (Article 6(1)(b) GDPR) — processing to carry out pre-contractual measures, for example when you request a market entry assessment.
- Art. 6 Abs. 1 lit. f DSGVO (Article 6(1)(f) GDPR) — our legitimate interest in a secure, stable and functioning website.
- § 25 Abs. 1 TDDDG (Section 25(1) of the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG, the German Telecommunications Digital Services Data Protection Act) — consent for storing information on your device or accessing information already stored there, where this is not strictly necessary.
- § 25 Abs. 2 Nr. 2 TDDDG (Section 25(2) no. 2 TDDDG) — storage without consent, where it is strictly necessary in order to provide the service you have expressly requested. Here this concerns only the storage of your cookie decision.
4. Hosting and delivery
This website is delivered via Cloudflare Pages. The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, represented in the EU by Cloudflare Germany GmbH, Rosental 7, 80331 München.
When a page is called up, your browser transmits technically necessary data that is processed in server log files: IP address, date and time of access, the URL requested, the volume of data transferred, the referrer URL, browser type and operating system. This data is necessary in order to deliver the pages and to defend against attacks; it is not merged with other data sources and is not used for profiling. The legal basis is Art. 6 Abs. 1 lit. f DSGVO (Article 6(1)(f) GDPR).
Cloudflare operates a worldwide server network; delivery usually takes place from a location within the EU. Processing in the USA cannot be entirely ruled out. A data processing agreement pursuant to Art. 28 DSGVO (Article 28 GDPR) including standard contractual clauses is in place with Cloudflare; Cloudflare, Inc. is also certified under the EU-U.S. Data Privacy Framework. Privacy policy: cloudflare.com/de-de/privacypolicy.
5. Fonts and embedded content
The font we use, IBM Plex Sans, is hosted entirely on our own server and loaded from there. There is no connection to Google Fonts or any other external font service; your IP address is not transmitted to third parties in this context.
We embed no external videos, map services, social media plug-ins or chat widgets. All images and icons are delivered from our own server.
6. Consent management (cookie banner)
On your first visit we ask whether you wish to allow statistics and marketing
techniques. We store your decision in your browser’s local storage
(localStorage) under the key mex-consent. Only the
categories you have selected and the time of the decision are stored — no IP address
and no identifier that makes you identifiable.
This storage is permitted without consent under § 25 Abs. 2 Nr. 2 TDDDG (Section 25(2) no. 2 TDDDG): without it we would have to ask you again on every page view. The entry remains on your device for twelve months; after that we obtain your decision again. The decision does not leave your device and is not transmitted to us or to third parties.
Withdrawal: you can withdraw your consent at any time with effect for the future — via the link in the footer or on this page. The lawfulness of the processing carried out up to the withdrawal remains unaffected. You can also clear your browser’s local storage; the initial state without analytics then applies again.
7. Google Tag Manager
To manage our analytics tags technically we use Google Tag Manager, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The Tag Manager itself sets no cookies and collects no personal data. It is a management tool that controls other services — here Google Analytics 4. The Tag Manager is only loaded into the page after you have given consent. Without your consent no Google script is requested, so no connection to Google servers is established and your IP address is not transmitted. Legal basis: Art. 6 Abs. 1 lit. a DSGVO (Article 6(1)(a) GDPR) in conjunction with § 25 Abs. 1 TDDDG (Section 25(1) TDDDG).
8. Google Analytics 4
With your consent we use Google Analytics 4
(measurement ID G-RMNSGVNJSZ), a web analytics service provided by Google
Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Our purpose is to
understand which of our professional content on entering the German market is found
and read, so that we can develop it further in a targeted way.
Which data is processed
- truncated IP address (truncation takes place within the EU before any further processing)
- approximate location at country and region level, derived from the IP address
- pages viewed, time spent, scroll depth and the order of the visit
- origin of the visit (search engine, referring website, campaign parameters)
- browser, operating system, device type and screen resolution
- interactions: clicks on calls to action, downloads of professional documents, clicks on email addresses and external links, and the start and successful submission of the contact form
When the contact form is submitted we transmit no form content in the narrower sense to Google — no name, no company, no email address and no message. Only the entries “Land” (country) and “Stand DE-Markt” (status in the German market) are transmitted, together with the information that an enquiry has been made.
Cookies
| Name | Purpose | Lifetime |
|---|---|---|
_ga | Distinguishes returning visits by means of a random identifier | 2 years |
_ga_RMNSGVNJSZ | Maintains the session state for this data stream | 2 years |
mex-consent | Your cookie decision. Not a cookie but an entry in local storage. Technically necessary, always set. | 12 months |
Settings we have made
- IP anonymisation is permanently enabled in Google Analytics 4 and cannot be switched off.
- Google signals and the collection of cross-device user identifiers are disabled. No merging with Google accounts takes place.
- The data is not passed on to Google for its own advertising purposes.
- The retention period for user and event data is limited to 14 months; after that the data is deleted automatically.
- Through Google consent mode (Consent Mode v2) all signals are set to “denied” by default and are only released after you have consented.
Transfers to third countries
Our contractual partner is Google Ireland Limited in Ireland. A transfer to Google LLC in the USA cannot be ruled out. Google LLC is certified under the EU-U.S. Data Privacy Framework; by decision of 10 July 2023 the European Commission established an adequate level of protection for that framework. In addition, standard contractual clauses pursuant to Art. 46 Abs. 2 lit. c DSGVO (Article 46(2)(c) GDPR) have been agreed. Despite these safeguards, transfers to the USA carry the residual risk of access by US authorities, against which you may have no equivalent legal remedies. By giving your consent you also consent to this transfer (Art. 49 Abs. 1 lit. a DSGVO, Article 49(1)(a) GDPR).
Legal basis: Art. 6 Abs. 1 lit. a DSGVO (Article 6(1)(a) GDPR) in conjunction with § 25 Abs. 1 TDDDG (Section 25(1) TDDDG). A data processing agreement pursuant to Art. 28 DSGVO (Article 28 GDPR) is in place with us. Further information: policies.google.com/privacy and business.safety.google/privacy.
9. Marketing category
The “Marketing” category in the consent dialogue is prepared for reach measurement of our professional communication, in particular for the LinkedIn Insight Tag. At present no active services are assigned to it: even where consent has been given, no marketing tag is currently executed. As soon as we deploy a service here, we will describe it at this point before it is activated.
10. Contact form
You can request a market entry assessment using the form on the contact page. The mandatory fields are name, company, role, country, email address and product category; telephone number, market status and message are optional. We process this information solely in order to answer your enquiry and to prepare a possible mandate.
The legal basis is Art. 6 Abs. 1 lit. b DSGVO (Article 6(1)(b) GDPR, pre-contractual measures) together with Art. 6 Abs. 1 lit. a DSGVO (Article 6(1)(a) GDPR) for the consent you give in the form. An invisible check field (“honeypot”) protects against automated submissions; it stores no data about you.
Processor Web3Forms
The technical transmission of the form runs through the service Web3Forms, operated by Web3Creative, a company registered in Kerala, India. Web3Forms receives your entries and forwards them by email to our mailboxes. Processing takes place on servers in the United States (US-East region) using the infrastructure providers Amazon Web Services, Cloudflare and Hetzner.
To ward off spam, Web3Forms may transmit your IP address and your email address to the checking services CleanTalk and Akismet (Automattic Inc.). According to its own statements, Web3Forms stores submitted form data for a maximum of three years and deletes server logs regularly.
Note on transfers to third countries: India and the USA are third countries for which the European Commission has issued no adequacy decision covering this provider. The transfer is safeguarded by a data processing agreement with standard contractual clauses pursuant to Art. 46 Abs. 2 lit. c DSGVO (Article 46(2)(c) GDPR). Even so, a level of protection equivalent to European standards cannot be guaranteed; in particular, equivalent legal remedies against access by public authorities may not be available. By submitting the form you consent to this transfer (Art. 49 Abs. 1 lit. a DSGVO, Article 49(1)(a) GDPR). If you wish to avoid this, please write to us directly at [email protected] instead.
The provider’s privacy policy: web3forms.com/privacy.
11. Contact by email
If you write to us directly by email, we process your sender address and the content of your message in order to answer the enquiry. The legal basis is Art. 6 Abs. 1 lit. b DSGVO (Article 6(1)(b) GDPR) for business-related enquiries, otherwise Art. 6 Abs. 1 lit. f DSGVO (Article 6(1)(f) GDPR). Please note that unencrypted email is not a secure transmission channel. For confidential documents — technical documentation or regulatory files, for example — we are glad to agree a non-disclosure agreement and a secure transmission channel in advance.
12. Retention periods
- Server log files: as a rule 30 days, then automatic deletion.
- Analytics data in Google Analytics 4: 14 months.
- Cookie decision: 12 months in your browser’s local storage.
- Enquiries via the form or by email: until they have been dealt with in full. If no mandate comes about, we delete them after six months at the latest. If the enquiry leads to a business relationship, the commercial and tax retention periods of six and ten years respectively apply (§ 257 HGB, Section 257 of the Handelsgesetzbuch, German Commercial Code; § 147 AO, Section 147 of the Abgabenordnung, German Fiscal Code).
13. Recipients of the data
Your data is received exclusively by bodies that we engage to provide our services and that are contractually bound by our instructions: Cloudflare (hosting), Web3Forms/Web3Creative (form transmission) and — only where consent has been given — Google Ireland Limited (analytics). No data is passed on for third-party advertising purposes. Within our company, only those people have access who need it in order to handle your enquiry.
14. Your rights
You have the following rights in relation to us:
- Access to the data processed about you (Art. 15 DSGVO, Article 15 GDPR)
- Rectification of inaccurate or incomplete data (Art. 16 DSGVO, Article 16 GDPR)
- Erasure, unless a retention obligation stands in the way (Art. 17 DSGVO, Article 17 GDPR)
- Restriction of processing (Art. 18 DSGVO, Article 18 GDPR)
- Data portability in a commonly used format (Art. 20 DSGVO, Article 20 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7 Abs. 3 DSGVO, Article 7(3) GDPR)
Right to object under Art. 21 DSGVO (Article 21 GDPR)
Where we process data on the basis of a legitimate interest (Art. 6 Abs. 1 lit. f DSGVO, Article 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation. We will then no longer process the data concerned, unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims.
Right to lodge a complaint
Irrespective of this, you may lodge a complaint with a supervisory authority (Art. 77 DSGVO, Article 77 GDPR). The authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
(the Hessian Commissioner for Data Protection and Freedom of Information)
Postfach 3163, 65021 Wiesbaden
datenschutz.hessen.de
15. Whether provision is required
This website can be used without providing personal data. If you request an assessment, we need the information marked as mandatory in order to classify your enquiry properly and answer it. Without this information we cannot process the enquiry. There is no statutory or contractual obligation to provide it.
16. No automated decision-making
There is no automated decision-making, including profiling, within the meaning of Art. 22 DSGVO (Article 22 GDPR). Your enquiry is decided on exclusively by people.
17. Changes to this policy
We adapt this policy when our website, the services we use or the legal situation change. The version published here applies in each case. If we add a new service that requires consent, we obtain your consent again beforehand.
Last updated: 31 July 2026