Privacy Policy
Protecting your personal data matters to us. This policy explains which data is processed when you visit this website, on what legal basis, and which rights you have.
1. Controller
Controller within the meaning of Art. 4 (7) GDPR:
Dr. med. Maurice Dellin c/o Medical Faculty of the University of Münster Albert-Schweitzer-Campus 1, Building A6 48149 Münster, Germany Email: medocs@uni-muenster.de
2. General information
We process personal data only where required to provide a functioning website and our content, or where you actively submit data to us. Legal bases are Art. 6 (1) (b) GDPR (handling enquiries), Art. 6 (1) (f) GDPR (legitimate interest in secure, stable operation) and — where applicable — Art. 6 (1) (a) GDPR (consent). This website uses no analytics, tracking or advertising services.
3. Hosting in Germany
This website runs on a server operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (data centre in Falkenstein/Vogtland, Germany). All website data — including the database holding content and form submissions — is processed and stored exclusively on this server in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner. Legal basis: Art. 6 (1) (f) GDPR.
4. DNS management (Cloudflare)
Name resolution for the domain medocs.ms is provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA — solely as a DNS service. Traffic to this website is not routed, cached or decrypted by Cloudflare; your connection is established directly with our server in Germany. Cloudflare is certified under the EU-US Data Privacy Framework.
5. TLS encryption
All connections to this website are TLS-encrypted (HTTPS). Certificates are issued automatically via Let’s Encrypt and managed directly on our server — encryption terminates with us, not at an intermediary.
6. Server logs
When you visit the website, the server processes technically necessary connection data (IP address, timestamp, requested resource, referrer, user agent, status code) to deliver content, analyse errors and fend off attacks. Logs are kept for a maximum of 14 days and are not merged with other data sources. Legal basis: Art. 6 (1) (f) GDPR.
7. Cookies and local storage
This website uses only technically necessary cookies and local storage: a cookie storing your language choice (German/English), a localStorage entry for the theme setting (light/dark), and — for editorial members only — a login cookie for the protected admin area. No consent is required for these under § 25 (2) no. 2 TTDSG, so no cookie banner is needed. We set no tracking or third-party cookies.
8. Contact and join forms
If you write to us via the contact or join form, we process the data you provide (name, email address, subject or semester, message) solely to handle your request. Submissions are stored in our own database on the server named above in Germany and are not shared with third parties. Spam protection relies on invisible technical checks (honeypot field, timing) — no external services, no tracking. Legal basis: Art. 6 (1) (b) or (a) GDPR. We delete the data once the purpose ceases and no statutory retention obligations apply.
9. Embedded videos (YouTube / Vimeo)
Some project pages embed videos. YouTube videos load via the privacy-enhanced domain youtube-nocookie.com (Google Ireland Ltd.); Vimeo videos load with the "Do Not Track" parameter enabled (Vimeo Inc., USA). Connection data is transmitted to the respective provider at the latest when you play a video, and is processed under their own policies. Legal basis: Art. 6 (1) (f) GDPR.
10. No analytics or tracking
We use no web analytics (e.g. Google Analytics), no ad networks, no social media plugins and no fingerprinting. Your visit is not profiled or evaluated by us.
11. External links
Our pages link to external websites (clinics, partners, platforms). When you follow such a link you leave our site; the privacy policy of the respective provider applies.
12. Your rights
You have the rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on Art. 6 (1) (f) GDPR (Art. 21). You may revoke any consent at any time with effect for the future — simply contact the address given in the legal notice. You also have the right to lodge a complaint with a supervisory authority; competent for us is the Data Protection Commissioner of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.
13. Data security
We apply technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, misuse and unauthorised access — including TLS encryption, a hardened server configuration with firewall, minimal access rights and separated credential management. The admin area is accessible to authorised members only.
14. Version and changes
Last updated: July 2026. We amend this policy when the website or the legal situation changes; the version published here applies.