Privacy Policy
1. Controller
Praxis für Dentale Ästhetik, Dr. med. dent. Cem Jak Hayim M.Sc. M.Sc., Rüttenscheider Str. 194–196, 45131 Essen, Germany. Phone: +49 201 48682900. Email: praxis@hayim.de.
2. Accessing the website and server logs
When the website is accessed, technically necessary connection data is processed. This may include the IP address, time, requested resource, referrer, and browser and system information. Processing serves the secure and stable provision of the website and the prevention of misuse. The legal basis is Art. 6(1)(f) GDPR. Log data is retained only for as long as required for operation, security and error analysis; longer retention occurs only in the event of a specific security incident or where required by law.
3. Technically necessary storage and consent
The website stores the necessary cookies `cd_consent_id` and `cd_consent` in order to remember an anonymous consent identifier, the selected category settings and the consent version used. The selection can be changed or withdrawn via the privacy settings. Cookie duration and the consent record are generally retained for twelve months; withdrawal applies for the future.
Non-essential categories, in particular analytics and external media, are activated only after the relevant consent has been given. The legal basis for storing or accessing non-essential information is Section 25(1) TDDDG; subsequent data processing is based on Art. 6(1)(a) GDPR.
4. Appointment request via the website form
The form transmits name, telephone number, optional email address, preferred language, type of appointment and preferred time. In addition, the consent version and time of acceptance, as well as a salted technical fingerprint used to prevent misuse and duplicate submissions, are stored. The request is not an automatic appointment confirmation.
Processing serves to handle your appointment request and pre-contractual communication in accordance with Art. 6(1)(b) GDPR. The free-text message field should not contain detailed health information. If health data is voluntarily submitted in an individual case, it is processed only for the purpose of handling the specific request. Request data is deleted once the purpose has been fulfilled and no statutory retention or evidence obligations prevent deletion.
5. Contact by telephone or email
If you contact us by telephone or email, we process the information you provide in order to handle your request. Depending on the content, the legal basis is Art. 6(1)(b) or (f) GDPR; where health data is involved, the requirements of Art. 9 GDPR also apply. Medical emergencies and particularly sensitive information should not be transmitted by unencrypted email.
6. External maps
An embedded external map is loaded only if the function is technically enabled and you have consented to the external-media category. Without consent, the address and a standard external route link remain usable. When the map is loaded, data — in particular the IP address and device information — may be transmitted to the map provider. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
7. Analytics, advertising and CLICKDOC
In the configuration prepared for publication, web analytics, advertising tags and CLICKDOC are not activated. Such services are not enabled merely by being mentioned in this privacy notice. If they are activated later, this will take place only after technical and data-protection review, an update to this notice and — where required — valid consent.
8. Recipients and processing on behalf of the controller
Access is limited to authorised employees and technically necessary service providers, in particular the hosting and email providers, insofar as this is required for operation and communication. Where a service provider processes personal data on our behalf, a data-processing agreement pursuant to Art. 28 GDPR is used. Transfers to third countries take place only where the statutory requirements are met.
9. Your rights
Within the framework of the law, you have the right to access, rectification, erasure, restriction of processing, data portability and objection. You may withdraw consent at any time with effect for the future. You may also lodge a complaint with a data-protection supervisory authority. The competent authority for non-public bodies in North Rhine-Westphalia is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.
10. Security and updates
We use appropriate technical and organisational measures. Data transmission over the internet may nevertheless involve security risks. This notice will be updated if functions, providers or legal requirements change.
Status: 16 August 2026.