Privacy policy — draft
1. Controller
The legally responsible controller and full contact details must be confirmed before publication.
[LEGAL REVIEW REQUIRED]
2. Hosting
The hosting provider, server location and contractual privacy arrangements will only be documented after the operating environment has been defined.
[LEGAL REVIEW REQUIRED]
3. Server log files
The type, scope, purpose and retention of possible server logs must be determined from the future server configuration.
[LEGAL REVIEW REQUIRED]
4. Contact
Processing during telephone or electronic contact can only be described after the contact channels and legal requirements have been confirmed.
[LEGAL REVIEW REQUIRED]
5. Appointment request
The current appointment request is in “disabled” mode. It sends no data, displays no success state and stores no form entries.
[LEGAL REVIEW REQUIRED]
7. External services
The current frontend uses no analytics, external tracking or external runtime embeds. Future services must be documented and reviewed before use.
[LEGAL REVIEW REQUIRED]
8. Data subject rights
Applicable rights, conditions and contact channels must be stated completely in a final legal version.
[LEGAL REVIEW REQUIRED]
9. Retention period
Specific storage and deletion periods can only be defined after the actual data processing and operating procedures have been confirmed.
[LEGAL REVIEW REQUIRED]
10. Data security
Technical and organisational measures must be described to match the future operating, transport and form configuration.
[LEGAL REVIEW REQUIRED]
11. Changes to this privacy policy
The update procedure, version status and publication information must be defined in the final legal version.
[LEGAL REVIEW REQUIRED]