Skip to Content

Privacy Policy

This is a translation and may contain errors. If in doubt, read the original German version.

Responsible

The responsible party in terms of the General Data Protection Regulation (GDPR) is:

simHEART GmbH Steinbachergasse 15 82487 Oberammergau Germany

Represented by the managing directors Johannes Krammer and Kamil Beranek

E-Mail: office@simheart.de
Contact form: Contact form

A data protection officer is not required to be appointed according to § 38 para. 1 BDSG.

1. General

1.1 What are personal data

Personal data are information that reveals or can reveal your identity. We adhere to the principle of data minimization. This means that personal data is not collected to the greatest extent possible.

1.2 Handling of personal data

As far as we process personal data, this is done on the basis of your consent, to fulfill a contract, or based on our legitimate interests in providing and optimizing our services. In doing so, we may use processors who process data on our behalf and according to our instructions. The processing generally takes place within the European Union or the European Economic Area or in countries for which the European Commission has issued an adequacy decision.

1.3 Usage data

When you access our website, information is automatically registered in so-called log files or in the log database due to technical conditions. This usage data includes in particular:

  • IP address
  • Date and time of access
  • called pages
  • used browser and browser version
  • used operating system
  • Referrer URL (the previously visited page)

This data is used for statistical evaluations but is not combined with other personal data.

When using our simulation platform simHEART, technical information about your device is transmitted to our server, in particular:

  • screen resolution and size of the browser window
  • browser and browser version
  • operating system and device type
  • IP address as well as date and time of access

The screen resolution and window size are read out to correctly display and scale the simulated device interface on your device. To this extent, access is absolutely necessary for providing the service you have explicitly requested (§ 25 Abs. 2 Nr. 2 TDDDG). Information about the browser, browser version, and operating system is automatically transmitted by your browser when establishing a connection.

Additionally, we store this technical information for the purpose of quality assurance as well as for analyzing and fixing technical errors, especially display-related errors. They are not combined with other personal data and not used for other purposes. The legal basis for this is Art. 6 Abs. 1 S. 1 lit. f GDPR (legitimate interest in the error-free operation and further development of our application).

The legal basis for processing usage data is Art. 6 Abs. 1 S. 1 lit. f GDPR (legitimate interest in the analysis, optimization, security, and economic operation of our website).

1.4 Electronic revocation of contracts

As far as you revoke a contract, especially a purchase contract, electronically, we process the following data to fulfill our legal documentation obligations:

  • Name
  • E-mail address
  • Contract details
  • Timestamp of the revocation
  • IP address

The legal basis is Art. 6 para. 1 sentence 1 lit. c GDPR (legal obligation).

1.5 Storage duration

Your personal data will only be stored as long as necessary for the respective purpose or as long as legal retention periods exist. The commercial and tax retention periods begin at the end of the calendar year in which the document was created. The following storage periods apply in detail:

  • Booking documents, especially incoming and outgoing invoices, account statements, and receipts: 8 years (§ 257 HGB, § 147 AO)
  • Books and records, annual financial statements, inventories, and opening balances: 10 years
  • Received and sent commercial and business letters: 6 years
  • Data protection consents: Duration of the consent plus the period during which rights can be asserted
  • Electronic correspondence: after completion or after the expiration of legal retention periods
  • Usage data (log files): maximum 30 days
  • Revocation documentation: after the expiration of the legal retention periods
  • Newsletter consents: Duration of the subscription plus the period during which rights can be asserted

The tax retention periods do not end as long as the documents are relevant for an ongoing procedure, especially an external audit.

2. Your rights

2.1 Information

You can request information from us about whether we process personal data about you, and to the extent that this is the case, you have the right to information about this personal data and the additional information mentioned in Art. 15 GDPR.

2.2 Right to Rectification

You have the right to rectification of inaccurate personal data concerning you and may request the completion of incomplete personal data in accordance with Art. 16 GDPR.

2.3 Right to Erasure

You have the right to request that we erase personal data concerning you without delay. We are obliged to erase this data without delay, especially if one of the following reasons applies: Your personal data are no longer necessary for the purposes for which they were collected or otherwise processed. You withdraw your consent on which the processing of your data is based, and there is no other legal basis for the processing. Your data have been processed unlawfully. The right to erasure does not exist insofar as your personal data are necessary for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims.

2.4 Right to Restriction of Processing

You have the right to request the restriction of the processing of your personal data from us if: you contest the accuracy of the data and we therefore verify the accuracy, the processing is unlawful and you refuse deletion and instead request the restriction of use, we no longer need the data, but you need it for the assertion, exercise, or defense of legal claims, or you have objected to the processing of your data and it is not yet clear whether our legitimate grounds override your grounds.

2.5 Right to Data Portability

You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us, provided that the processing is based on consent or a contract and the processing is carried out by us using automated procedures.

2.6 Right of Withdrawal and Objection

Insofar as the processing of your personal data is based on consent (Art. 6 para. 1 sentence 1 lit. a GDPR), you have the right to withdraw this consent at any time in accordance with Art. 7 para. 3 GDPR. This does not affect the lawfulness of the processing based on the consent until the withdrawal.

As far as the processing of your personal data is based on Art. 6 para. 1 sentence 1 lit. e GDPR or Art. 6 para. 1 sentence 1 lit. f GDPR, you have the right under Art. 21 GDPR to object at any time to the processing of personal data concerning you for reasons arising from your particular situation. We will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

2.7 General and Right to Complain

The exercise of your aforementioned rights is generally free of charge for you. Regardless, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority, particularly in the member state of your residence, your workplace, or the place of the alleged infringement.

The supervisory authority responsible for us is:

Bavarian State Office for Data Protection Supervision (BayLDA) Promenade 18 91522 Ansbach Mailing address: P.O. Box 1349, 91504 Ansbach E-Mail: poststelle@lda.bayern.de https://www.lda.bayern.de

2.8 Automated Decision-Making Including Profiling

Automated decision-making pursuant to Art. 22 GDPR, meaning decisions that are based solely on automated processing including profiling and have legal effects or significantly affect you in a similar manner, does not take place with us.

3. Data Security

3.1 Technical and Organizational Measures

All data you provide will be secured on our website through technical and organizational measures against loss, destruction, unauthorized access, alteration, and distribution. The transmission is encrypted via TLS.

3.2 Cookies and Consent Management

Cookies or information on your end device will only be stored or read without your consent if this is absolutely necessary for the provision of the digital service you have explicitly requested (§ 25 para. 2 no. 2 TDDDG). For marketing, analysis, and personalization purposes, as well as for sharing with partners, we require your explicit consent (§ 25 para. 1 TDDDG) and, to the extent that personal data is processed, your consent according to Art. 6 para. 1 sentence 1 lit. a GDPR.

Which cookies are used on our website and in our shop, for what purpose, and how long they are stored can be found in our cookie policy:

www.simheart.de/cookie-policy

Your consent decision will be stored so that it does not have to be asked again on subsequent page views. You can change or revoke your selection at any time via the cookie settings on our website with effect for the future. The legal basis for documenting consent is Art. 6 para. 1 sentence 1 lit. c GDPR in conjunction with Art. 7 para. 1 GDPR as well as our legitimate interest in the legally compliant design of our website (Art. 6 para. 1 sentence 1 lit. f GDPR).

3.3 Cookies and Local Storage in the simHEART Application

The simulation platform simHEART (simheart.app) is a standalone web application. The aforementioned cookie policy applies to the website and shop; only the following technically necessary storage mechanisms are used in the application itself. There are no analysis, statistics, marketing, or third-party cookies set, there is no profiling taking place and there are no third-party contents (e.g., external fonts, CDN, tracking pixels) loaded.

Cookies

DesignationCategoryPurposeStorage Duration
PHPSESSID (Session Cookie)technically necessaryAssignment of your session and maintenance of the login during useEnd of session (deletion upon closing the browser)
token (remember login)technically necessarypermanent login if you keep the option 'Stay logged in' activated during login; contains a random identifier that is stored server-side only as a cryptographic hash value180 days from issuance; upon further use, the period is renewed. Deletion immediately upon logout as well as with every password change
language_id (language setting)technically necessaryStorage of the display language you have chosen on the login, password, and invitation page; contains only a language numberEnd of session

All cookies are set with the protection attributes HttpOnly (no access by scripts; except for language_id), SameSite=Lax, and – in case of an encrypted connection – Secure.

Local storage on your device

In order for simHEART to be reliably usable in class even with weak or temporarily interrupted internet connection, the application stores content in the memory of your browser or your installed web app. This only includes teaching and media content of the application, not personal data.

DesignationCategoryPurposeStorage Duration
simheart (IndexedDB)technically necessarylocal caching of library content (images and associated directory data) when accessing the library as well as – at your explicit selection via "Download media" in the settings – for offline useuntil you delete the application storage or the browser data; starting from a size of about 600 MB, the least recently used content will be automatically removed
sound-cache-v1 (Cache Storage / Service Worker)technically necessarylocal storage of alarm and device sounds of the simulation, so that they can be played offline and without additional data consumptionuntil you delete the application storage or the browser data

The application additionally requests your browser to classify this storage as "permanent" so that the downloaded content is not automatically discarded by the operating system. You can delete this data at any time by removing the website data for simheart.app in your browser settings or by deleting the installed web app. This does not result in a loss of usage data, as all your account and simulation data is stored on the server.

Your personal application settings (e.g., display and device settings of the simulators) are not stored on your device, but server-side in your user account, so that they are available to you on any device.

Sämtliche der genannten Speichervorgänge sind für die Erbringung des von Ihnen ausdrücklich gewünschten Dienstes unbedingt erforderlich. Eine Einwilligung ist dafür nach § 165 Abs. 3 TKG 2021 nicht erforderlich; die Verarbeitung der damit verbundenen Daten erfolgt auf Grundlage von Art. 6 Abs. 1 lit. b DSGVO (Erfüllung des Nutzungsvertrags) sowie Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an einem sicheren und funktionsfähigen Betrieb).

4. Contact Form

If you send us inquiries via the contact form or by email, your information, including the contact details you provided there, will be stored by us for processing your inquiry and for possible follow-up questions. The legal bases for this are Art. 6 para. 1 lit. b GDPR (pre-contractual measures), Art. 6 para. 1 lit. f GDPR (legitimate interest in responding to your inquiry), or your consent (Art. 6 para. 1 lit. a GDPR). The data will remain with us until the storage purpose ceases or you revoke your consent, while statutory retention periods remain unaffected.

5. Newsletter

If you subscribe to our newsletter, we use a so-called double opt-in procedure. This means that after your registration, we will send you an email to the provided address asking you to confirm that you wish to receive the newsletter. The legal basis for sending the newsletter is your consent according to Art. 6 para. 1 sentence 1 lit. a GDPR. To prove your consent, we store the date, time, and email address (legal basis: Art. 6 para. 1 sentence 1 lit. c GDPR). You can revoke your consent at any time and unsubscribe from the newsletter via the unsubscribe link, by email, or in writing.

6. Customer Account and Registration

If you create a customer account through our website, we will process the data you entered during registration (such as your name, address, or email address) exclusively for pre-contractual services, for contract fulfillment, or for customer care purposes, such as providing you with an overview of your previous orders. At the same time, we store the IP address as well as the date and time of your registration. This data will not be shared with third parties.

As part of the registration process, your consent for this processing is obtained and reference is made to this privacy policy. To the extent that you consent to this processing, Article 6(1)(a) GDPR is the legal basis. If the opening of the customer account also serves pre-contractual measures or contract fulfillment, the legal basis is also Article 6(1)(b) GDPR.

You can revoke the consent granted to us for the opening and maintenance of the customer account at any time with effect for the future in accordance with Article 7(3) GDPR. To do this, you only need to inform us of your revocation.

The collected data will be deleted as soon as the processing is no longer necessary. Tax and commercial law retention periods remain unaffected.

7. Contract Fulfillment

The data you provide to use our goods and services is processed for the purpose of contract processing. The conclusion of the contract and contract processing are not possible without providing this data. The processed data includes in particular:

  • First and last name
  • Billing address
  • Delivery address (if different)
  • E-mail address
  • Phone number (optional)
  • Order details and order history
  • Payment information

The legal basis for processing is Article 6(1)(b) GDPR. We delete the data upon complete contract fulfillment while observing the tax and commercial law retention periods.

As part of the contract processing, we will pass your data to the transport company commissioned with the delivery or to the payment service provider, as far as the transfer is necessary for delivery or payment purposes. The legal basis for the transfer is Art. 6 para. 1 lit. b GDPR.

8. Use of Third-Party Services

8.1 Website, Shop, and Customer Account (Odoo Online)

This website is operated with the software Odoo and is hosted as part of the Odoo Online service at Odoo S.A., Chaussée de Namur 40, 1367 Grand-Rosière, Belgium. All data collected through this website, particularly contact inquiries, customer account and order data, as well as server log files, are processed in this environment.

Odoo processes this data exclusively on instructions as a processor. We have entered into a processing agreement with Odoo in accordance with Art. 28 GDPR.

Our database is assigned to the hosting region Europe. According to the provider, the production systems of this region are located in France and Belgium, with redundant backups in France, the Netherlands, and Sweden. Odoo uses its own subcontractors for this purpose, particularly OVH S.A.S. and Google Cloud EMEA Ltd.

To provide the website, Odoo uses technically necessary cookies, for example, for session management, to store the selected language and time zone, and to retain the shopping cart contents. You can find details in our cookie policy (see section 3.2).

The legal basis is Art. 6 para. 1 lit. b GDPR (contract fulfillment) as well as Art. 6 para. 1 lit. f GDPR (legitimate interest in a secure and efficient provision of our online services).

Provider's privacy policy: https://www.odoo.com/de_DE/privacy

8.2 Hosting of the simulation platform simHEART

The simulation platform simHEART is hosted at TeraIT e.U., Wienerstraße 47, 2000 Stockerau, Austria. As physical server infrastructure, our host utilizes data center capacities of Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. The servers are located exclusively in Germany, so the processing takes place within the European Union.

Specifically, IP addresses, access, meta and communication data, usage data, as well as the content entered during the simulation are processed.

The use is for the fulfillment of the contract with our customers (Art. 6 para. 1 lit. b GDPR) and in the interest of a secure, fast, and efficient provision of our services (Art. 6 para. 1 lit. f GDPR). The host processes your data only to the extent necessary to fulfill its service obligations and follows our instructions. A contract for data processing according to Art. 28 GDPR has been concluded with the host as well as with Hetzner Online GmbH.

8.3 Web analysis and usage statistics

Google Analytics 4

This website uses Google Analytics 4, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The use of Google Analytics 4 and the setting of the associated cookies only occurs with your explicit consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR. Google Analytics 4 truncates your IP address within the EU or the EEA before it is transmitted. The data may also be transmitted to and processed by Google LLC and Alphabet Inc. in the USA. User-related data is automatically deleted after 2 months.

You can prevent the storage of cookies, use a browser plug-in at https://tools.google.com/dlpage/gaoptout or revoke your consent at any time through the cookie settings. Transfers to the USA are based on the adequacy decision of the European Commission of July 10, 2023 (EU-US Data Privacy Framework).

More information: https://policies.google.com/privacy

8.4 Payment service providers and payment methods

To process payments, we use the payment service provider mentioned below. If you choose one of the payment methods offered through it, the personal data required for payment processing will be transmitted to it. The processing is carried out to fulfill the contract (Art. 6 para. 1 sentence 1 lit. b GDPR).

Stripe

Provider for customers within the European Economic Area: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland

Privacy Policy: https://stripe.com/de/privacy

Privacy Center: https://stripe.com/de/legal/privacy-center

If you choose a payment method offered via Stripe, we will transmit the data required for processing to Stripe, in particular your name, billing address, email address, order and billing information, as well as the transaction number. You will enter your payment data, such as the card number, directly into an input form provided by Stripe. This data will not be known to us and will not be stored by us. Stripe uses its own cookies during the payment process, which are necessary for processing the payment and for fraud prevention.

Stripe also processes data in the USA. Transfers to the USA are based on the EU-US Data Privacy Framework and on standard contractual clauses according to Art. 46 GDPR. To the extent that Stripe processes data on our behalf, there is an agreement for data processing according to Art. 28 GDPR. Stripe is independently responsible for the payment processing itself, particularly for fraud prevention as well as for regulatory and anti-money laundering obligations.

Advance payment by bank transfer

If you choose advance payment, we will provide you with our bank details with the order confirmation or invoice. You will process the payment directly through your bank, and no payment service provider will be involved. In this context, we process the information transmitted to us with the payment receipt, in particular account holder, IBAN, amount, booking date, and purpose of use, for the allocation of the payment and for accounting.

The legal basis is Art. 6 para. 1 sentence 1 lit. b GDPR. For the subsequent storage of payment receipts, the legal basis is Art. 6 para. 1 sentence 1 lit. c GDPR in conjunction with the commercial and tax-related storage obligations (see section 1.5).

9. Social Media Presences

We maintain online presences within social networks to communicate with customers, interested parties, and users active there and to inform them about our services. When accessing the respective networks and platforms, the terms and conditions and data processing policies of the respective operators apply.

Unless otherwise stated, we process the data of users if they communicate with us within the social networks, for example, by writing posts on our online presences or sending us messages. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR. Our legitimate interest lies in communication as well as in promoting our products and services. The legal basis may also be a user's consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR.

9.1 Joint Responsibility

For some social media platforms, there is joint responsibility according to Art. 26 GDPR regarding the processing of insights data (usage statistics). The details are regulated in the respective agreements on joint responsibility.

9.2 Facebook

Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

Privacy Policy: https://www.facebook.com/about/privacy/

Agreement on Joint Responsibility (Page Controller Addendum): https://www.facebook.com/legal/terms/page_controller_addendum

Data processing may also occur through Meta Platforms, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. Data transfers to the USA are secured by the EU-US Data Privacy Framework.

9.3 Instagram

Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

Privacy Policy: https://privacycenter.instagram.com/policy/

Agreement on Joint Responsibility (Page Controller Addendum): https://www.facebook.com/legal/terms/page_controller_addendum

Data processing may also occur through Meta Platforms, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. Data transfers to the USA are secured by the EU-US Data Privacy Framework.

9.4 LinkedIn

Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland

Privacy Policy: https://www.linkedin.com/legal/privacy-policy

Agreement on Joint Responsibility (Pages Joint Controller Addendum): https://legal.linkedin.com/pages-joint-controller-addendum

Data processing may also occur through LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA. Data transfers to the USA are secured by the EU-US Data Privacy Framework.

9.5 YouTube

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

Privacy Policy: https://policies.google.com/privacy

Data processing may also occur through Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Data transfers to the USA are secured by the EU-US Data Privacy Framework.

10. Telemedicine Module

As part of the telemedicine module of simHEART, the following information can optionally be provided for the simulated session participants as well as the simulated doctor: name, phone number, and qualification. Providing this information is voluntary; the corresponding fields can remain empty. Through the integrated chat function, text messages and images can be exchanged between the session participants. All patient data presented in the module is simulated and fictitious; the transmission of real personal health data is not intended and not permitted.

The legal basis for processing the core data of the session is Art. 6 para. 1 sentence 1 lit. b GDPR (contract fulfillment). The voluntarily provided participant data (name, phone number, qualification) is processed on the basis of Art. 6 para. 1 sentence 1 lit. f GDPR (legitimate interest in the complete provision of the contractually agreed simulation functions). All data entered during a telemedicine session will be automatically and irrevocably deleted upon termination of the session. There is no permanent storage of session data. The processing of session data takes place on servers located in Germany (see section 8.2).

For audio and video calls, the telemedicine module only provides links to external communication services (currently WhatsApp and Signal). The actual communication is fully handled through these external services; simHEART does not provide its own infrastructure for this purpose. The data processing associated with the use of these services is solely the responsibility of the respective providers:

We recommend that you familiarize yourself with the privacy policies of these services before using them. We have no influence over the data processing by these providers and accept no responsibility for this.

11. Changes to this Privacy Policy

We will adjust this privacy policy as soon as changes to our services or the legal situation make this necessary. The version published on this page applies.

Status: August 2026