Privacy Notice
Last updated 10 September 2026
1 Who is responsible for your data
The controller responsible for the processing described in this notice is:
adiphea GmbH
Dr. Lutz E. Kraushaar
Zieglersgrübe 47
97956 Werbach
Germany
Email: lutz.kraushaar@adiphea.com
Telephone: +49 151 6722 5287
Commercial register: Amtsgericht Mannheim, HRB 729404. VAT identification number: DE194469299.
You may use the email address above for any privacy question or request.
2 What this notice covers
This notice applies when you visit lutzkraushaar.com, contact us, use a booking link, complete a Double Check Doc or cardiovascular evidence review form, purchase a service, submit records, receive a report, or communicate with us about a service. It also explains the limited use of external providers that support hosting, forms, payment, AI-assisted analysis and secure delivery.
The services are intended for adults. Please do not submit information about a child or another person unless you are legally entitled to do so and have first contacted us.
3 The data we process
Depending on how you use the website and services, we may process:
Contact and identification data, such as your name, email address, country and correspondence details.
Technical website data, such as IP address, date and time, requested page, referrer, browser, operating system, device information and security logs.
Service-selection data, including the level you are considering, the question you want the report to address, the number and type of documents available and information needed to assess whether the request is in scope.
Health data that you choose to provide, including laboratory results, medical history, medication information, written imaging reports, measurements and other records relevant to the agreed review. Health data are special-category personal data under Article 9 GDPR.
Contract and payment data, such as the selected service, price, payment status, transaction reference, billing details and information needed for invoices and bookkeeping. We do not receive or store your full payment-card number.
Working and output data, including structured extracts, calculations, pseudonymized analysis files, quality-control notes and the final report.
Communication and scheduling data, including emails, booking details, questions, correction requests and service correspondence.
We normally receive these data directly from you. Stripe also supplies payment status and transaction identifiers. If a record contains another person’s data, you must remove it unless it is necessary and you have the right to provide it.
4 Why we process the data and the legal bases
| Purpose | Data and legal basis |
|---|---|
| Operate and secure the website | Technical data. Article 6(1)(f) GDPR: our legitimate interest in a reliable and secure website. |
| Remember cookie choices and use optional technologies | Article 6(1)(a) GDPR and section 25(1) TDDDG for consent-based access or storage; section 25(2) TDDDG and Article 6(1)(f) GDPR where technically necessary. |
| Answer enquiries and assess service fit | Article 6(1)(b) GDPR for steps requested before a contract; Article 6(1)(f) GDPR for general enquiries. Health data are processed only with explicit consent under Article 9(2)(a) GDPR. |
| Perform the purchased service | Article 6(1)(b) GDPR. Health data are processed with explicit consent under Article 9(2)(a) GDPR. |
| Process payment and prevent fraud | Article 6(1)(b), Article 6(1)(c) and, for security and fraud prevention, Article 6(1)(f) GDPR. |
| Use pseudonymized AI assistance | Article 6(1)(b) GDPR and explicit consent under Article 9(2)(a) GDPR, limited to the agreed analysis and report production. |
| Deliver the report securely | Article 6(1)(b) GDPR and, where health data are involved, explicit consent under Article 9(2)(a) GDPR. |
| Keep legally required business records and handle claims | Article 6(1)(c) GDPR for tax and commercial obligations; Article 6(1)(f) GDPR for establishing, exercising or defending legal claims. |
You may withdraw consent at any time with effect for the future by emailing us. Withdrawal does not affect processing that was lawful before withdrawal. Because health data are necessary for an individualized report, we cannot continue the service if you withdraw the relevant consent before completion. Any contractual consequences are governed by the Consumer Service Terms and mandatory law.
5 Website hosting and logs
The website is hosted by Host Europe GmbH, c/o Spaces, Gertrudenstraße 30–36, 50667 Cologne, Germany. Host Europe processes technical connection and log data so that the website can be delivered and protected. The legal basis is Article 6(1)(f) GDPR. Log data are retained only for as long as required for operation, security, troubleshooting and legal obligations, according to the hosting configuration and the provider’s applicable retention periods.
6 Cookies and consent management
We use Complianz on the WordPress website to record and manage cookie choices. Technologies that are not strictly necessary are activated only after the required consent. You may change or withdraw your choice at any time using the privacy or cookie settings displayed on the website. The current categories, providers, purposes and durations of cookies and similar technologies are shown in the website’s cookie policy or consent interface. Withdrawing consent does not affect the lawfulness of earlier processing.
7 Contact and appointment booking
If you contact us, we process the information you provide to answer the enquiry, take requested pre-contract steps or perform the contract. Please do not send health records by ordinary email. Where the website links to YouCanBookMe, booking data are processed through AI Software (Capacity) UK Ltd, trading as YouCanBookMe, Bedford Heights, Brickhill Drive, Bedford MK41 7PH, United Kingdom. YouCanBookMe acts as a processor for booking data. Its infrastructure is hosted in the United States and transfers are covered by contractual safeguards described by the provider. Do not enter health details in a booking form.
8 Tally forms and health-data intake
We use Tally, a service of Tally BV, Sint-Pietersnieuwstraat 11, 9000 Ghent, Belgium, enterprise number 0776.979.007. adiphea GmbH decides what the forms ask and is the controller for your responses; Tally acts as our processor. Tally states that form data are encrypted in transit and at rest and stored in Europe. File-upload and notification features may involve Tally subprocessors, including providers outside the European Economic Area, under the safeguards described in Tally’s data-processing terms.
The first form is used to identify the scope you want and assess whether the proposed material fits a service level. If you proceed, a paid intake form collects the information and documents required for the selected service. Please submit only relevant records, remove national identification numbers, insurance numbers, full street addresses and unrelated third-party information, and do not upload raw imaging files, DICOM files, ECG waveforms or other material outside the stated scope.
Tally form responses are not used for advertising by adiphea GmbH. We configure access to be limited to the service workflow and delete submissions according to Section 13 below.
9 Stripe payment processing
Payments are processed by Stripe. For an account located in the European Economic Area, the relevant Stripe contracting and data-processing entity is generally Stripe Payments Europe, Limited, Ireland; Stripe Technology Europe, Limited and Stripe Technology Company, Limited may also act as controllers for regulated payment and other activities. The precise Stripe entity and role depend on the payment method and context.
Stripe receives payment and billing information, device and connection data, order details, fraud-prevention signals and a transaction or customer reference. Stripe acts partly as our processor and partly as an independent controller for matters such as payment-network operation, fraud prevention, compliance and product security. We receive payment status and identifiers but not your full card number. Stripe may process data internationally using adequacy decisions, the EU Standard Contractual Clauses and other lawful transfer mechanisms. Stripe’s privacy information is available at https://stripe.com/privacy.
Do not enter health information in Stripe checkout fields. The payment description and internal service reference are kept general and are not intended to disclose medical details.
10 AI-assisted analysis and human review
We use the OpenAI API as an assisting tool for structured extraction, comparison, consistency checking and report drafting. Before material is sent to the API, we remove direct identifiers where practicable and replace them with an internal case reference. The separate link between that case reference and your identity is not sent to OpenAI. Only information reasonably needed for the agreed analysis is submitted.
For customers established in the European Economic Area, OpenAI Ireland Ltd. is the contracting processor under OpenAI’s Data Processing Addendum. OpenAI states that API data are not used to train its models unless the customer expressly opts in; adiphea GmbH does not opt in. Under the standard API configuration, prompts and responses may appear in abuse-monitoring logs for up to 30 days. We use an eligible API endpoint with storage disabled and do not create persistent assistants, threads, vector stores or files for client cases unless a later privacy notice expressly describes that configuration.
The AI tool does not decide whether you have a disease, what treatment you should receive or what action your doctor should take. Dr. Lutz E. Kraushaar reviews the relevant inputs, checks the analysis and takes responsibility for the final report. No decision producing legal or similarly significant effects is made solely by automated processing within this service.
The service provides epidemiological and biostatistical evidence interpretation to support better-informed discussion and shared decision-making with a physician. It is not diagnosis, medical advice, prescribing, treatment instruction, emergency assessment or a substitute for care by a licensed clinician.
11 Secure report delivery through Tresorit
We use Tresorit to provide an encrypted download link for the final report. Tresorit services are provided by Tresorit AG, Pfingstweidstrasse 60b, 8005 Zurich, Switzerland, company number CHE-349.825.210. Under a business subscription, Tresorit acts as a processor for content handled on our instructions and may process necessary delivery metadata. Switzerland is covered by an adequacy decision of the European Commission. The download link may expire, and you should store your own copy promptly. Health records should continue to be submitted through the designated Tally intake unless we expressly give you a different secure upload route.
12 Other recipients and disclosures
Access is limited to adiphea GmbH and providers needed to operate the service. We may also disclose information to professional advisers, public authorities, courts or other recipients where required by law or necessary to establish, exercise or defend legal claims. We do not sell client health data and do not use them for third-party advertising. We do not use client records to train our own or a third party’s general-purpose AI model.
13 Retention and deletion
| Record | Pilot retention rule |
|---|---|
| Initial selection or eligibility response when no purchase follows | Deleted within 14 days after the assessment or last relevant contact. |
| Paid intake, uploaded records, pseudonymized working files and our retained copy of the final report | Deleted within 90 days after report delivery, unless you request earlier deletion and no legal exception applies. |
| Secure delivery link and delivery copy | Configured to expire or be removed no later than 90 days after delivery. |
| Routine service correspondence | Deleted when no longer needed; limited contract correspondence may be retained for the applicable limitation period where necessary for claims. |
| Invoices, payment and accounting records | Retained for the statutory periods required by German tax and commercial law. Health records are not attached to accounting records. |
| Provider backups | Deletion from backup systems may follow the provider’s documented backup cycle. Tally states that deleted form data are removed from backups within 90 days, or earlier when its Trash is manually emptied. |
A legal hold, dispute, payment reversal, fraud investigation or binding legal duty may require longer retention of a limited record. When the reason ends, the data are deleted or anonymized.
14 Whether you must provide data
You are not legally required to provide personal or health data. Certain information is, however, necessary to assess scope, take payment and produce an individualized report. If you do not provide the necessary information or explicit health-data consent, we cannot offer or complete that service. You may ask general questions without submitting health records.
15 International transfers
Some providers or their subprocessors may process data outside the European Economic Area. Where GDPR requires a transfer mechanism, we rely on an adequacy decision, the European Commission’s Standard Contractual Clauses with supplementary safeguards, or another lawful mechanism. Tally stores form data in Europe but may use non-EEA subprocessors for optional functions. Stripe operates a global payment infrastructure. OpenAI may process API data outside the EEA under its DPA and transfer safeguards. Tresorit is established in Switzerland, which has an EU adequacy decision.
16 Your rights
Subject to the conditions and exceptions in applicable law, you may request access to your personal data, correction, deletion, restriction, data portability, and information about recipients. You may object to processing based on legitimate interests and withdraw consent with effect for the future. You also have the right to lodge a complaint with a supervisory authority.
The supervisory authority responsible for adiphea GmbH is: The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, Germany; email poststelle@lfdi.bwl.de; website https://www.baden-wuerttemberg.datenschutz.de.
To exercise a right, contact lutz.kraushaar@adiphea.com. We may ask for proportionate information to verify your identity. We will not ask you to send health records merely to verify a privacy request.
17 Security and your role
We use access controls, encrypted services, data minimization, pseudonymization and deletion routines appropriate to the pilot workflow. No internet service can guarantee absolute security. You can reduce risk by using the designated forms and delivery link, redacting unnecessary identifiers, keeping the case reference and download link private, and avoiding ordinary email for health records.
18 Changes to this notice
We may update this notice when the service, providers or law changes. The current version and its revision date will be posted on this page. A material change affecting an active client case will be communicated where required.