This Privacy Policy informs you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), about the processing of your personal data when using the McGesund platform. Unless expressly designated otherwise below, the definitions refer to the terms defined in Article 4 GDPR.
1. Controller
The controller within the meaning of Article 4(7) GDPR is:
Organon Informationssysteme GmbH
Karlstraße 31
63571 GelnhausenAuthorised representative: Helmut Fuhrmann (Geschäftsführer)
Commercial Register: Amtsgericht Bad Homburg v.d.H. HRB 8252
VAT ID: DE114153271
For questions regarding data protection, please contact:
Email: info@mcgesund.de
Telephone: +49 (0) 69 9043 1680
2. Scope and Orientation of the Platform
(1) User accounts and paid services are directed exclusively at entrepreneurs within the meaning of § 14 BGB; a contractual relationship exists only with them.
(2) The public directory is additionally open to private individuals who search, view and rate entries; no user account is required for this.
(3) Data of reviewers and signal senders is processed exclusively anonymously or pseudonymously. Clear-name data is accessible neither to the provider nor to the rated business customer.
(4) If a person applies via a published job offer, clear-name and contact data as well as the content of the application are processed in plain text for that purpose and transmitted to the advertising company. Details are set out in Section 20.
3. General Information on Data Processing
(1) Personal data is collected as a matter of principle only to the extent necessary to provide a functional platform, its content and services.
(2) Processing is carried out on one of the following legal bases:
- consent of the data subject — Article 6(1)(a) GDPR;
- performance of a contract or implementation of pre-contractual measures — Article 6(1)(b) GDPR;
- compliance with a legal obligation — Article 6(1)(c) GDPR; or
- safeguarding of legitimate interests — Article 6(1)(f) GDPR.
(3) The legal basis applicable in each case is expressly stated for each processing activity in the sections below.
4. Collection and Storage When Visiting the Website
(1) When the platform is accessed, information is automatically sent to our server by the browser used by your device and temporarily stored in a so-called log file. The following information is collected without any action on your part:
- IP address of the requesting device;
- date and time of access;
- name and URL of the file retrieved;
- website from which the access originates (referrer URL);
- browser used and, where applicable, the operating system of your device.
(2) This data is processed for the purpose of stable operation, the defence against attacks and the identification of errors.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in security and operational stability).
Storage period: a maximum of seven days; thereafter anonymisation or deletion, unless a specific incident makes longer storage necessary for investigation.
5. Registration and User Account
(1) In order to use the paid functions and to create a listing, you set up a user account. In doing so, we process the following personal data:
- first and last name;
- business email address;
- password (stored as a cryptographic fingerprint, not in plain text);
- where applicable, company name, address and telephone number;
- where applicable, value-added tax identification number.
(2) If you register via a single sign-on provider (Google, Microsoft or Apple), profile data transmitted by the respective provider is additionally processed — namely first name, last name, email address and a unique account identifier. In the case of Apple, an anonymised relay address may optionally be transmitted instead of your real email address ("Hide My Email").
(3) Registration takes place via the central authentication domain auth.mcgesund.eu. After successful sign-in, you are redirected to the brand domain originally accessed — in particular mcgesund.de, mcgesund.at, mcgesund.ch or mcgesund.eu. A separate session cookie is set on the brand domain; the session cookie of the authentication domain serves exclusively for the single sign-on and is not transmitted to the brand domain.
Legal basis: Article 6(1)(b) GDPR (performance of a contract).
Storage period: for the duration of the contractual relationship plus statutory retention periods (§ 147 AO, § 257 HGB — regularly six or ten years respectively).
6. Two-Factor Authentication
(1) You may optionally protect your user account by means of a second authentication factor. Upon activation, depending on the procedure chosen, we store
- in the case of an authenticator app: a cryptographic secret key per account together with a list of ten one-time emergency codes;
- in the case of a passkey or hardware security key: the public key of the authentication device in accordance with the FIDO2/WebAuthn standard.
(2) Private keys and biometric features never leave your device.
Legal basis: Article 6(1)(b) GDPR in conjunction with Article 32 GDPR (security of processing).
7. "Reviews" Module
(1) In the "Reviews" Module, we process data of end customers who submit a review via a QR code:
- content of the review and heart rating across four categories;
- location information of the device at the time of submission (geo-verification against the stored coordinates of the reviewed location);
- UI language used by the device;
- timestamp.
(2) A review is recorded without collecting the reviewer's real name. An optional response function enables the business customer to react publicly to the review; the response is published under the company name.
(3) To ensure authenticity, the platform cryptographically signs each review prior to storage (Ed25519 and, as of the "Klassik" Plan, additionally quantum-resistant using Falcon and/or ML-DSA). The signing keys themselves — not the review content — are anchored to the Bitcoin blockchain via OpenTimestamps. Personal data of reviewers is not stored in the blockchain.
(4) Reviews submitted via the reception display (rotating one-time QR code) bear the "Display-verified" marker; technically, no additional personal data points arise compared with the regular QR procedure.
Legal basis: Article 6(1)(a) GDPR (consent to publication of the review) as well as (f) (legitimate interest in protection against manipulation).
Storage period: permanent storage of the pseudonymised review as part of the reputation history of the location; deletion upon reasoned request, provided that no conflicting retention obligations exist.
8. "Signals" Module (Care Facilities)
(1) In the "Signals" Module, feedback from day-to-day care operations is recorded in six predefined categories. Capture is carried out anonymously:
- no real names, resident identifiers or other directly identifying data are collected;
- assignment is made solely via the Capture Unit (for example room, bed, ward, residential group or building);
- from the Provider's perspective, no personal reference to residents and patients arises.
(2) The business customer — the care facility — is the controller within the meaning of Article 4(7) GDPR for the processing at the installation site and is obliged to provide suitable notices pursuant to Article 13 GDPR at the location of the QR code.
(3) Insofar as the business customer transmits personal data of employees (for example task assignment by name in the workflow) to the platform, this is done on the basis of a separate data processing agreement pursuant to Article 28 GDPR. The Provider shall provide the template agreement on request.
Legal basis: Article 6(1)(b) GDPR (vis-à-vis the business customer) and — insofar as the business customer transmits personal data — Article 28 GDPR.
9. Cookies and Comparable Technologies
(1) We use exclusively technically necessary cookies and comparable storage technologies of the device — in particular browser storage (localStorage and sessionStorage) — that are required for the operation of the platform. These include in particular:
- session and authentication cookies (maintenance of the login session, cross-site request forgery defence) — storage period: for the duration of the session or until logout, at most 30 days;
- security cookies (anti-bot, rate limiting) — storage period: up to 24 hours;
- preference data in browser storage (e.g. language and theme selection, sidebar state) — storage period: until manual deletion by the user or until the browser is reset;
- device token in browser storage for the reception display (only where the display function is active, as of the "Klassik" Plan) — storage period: until the token is revoked in the customer account.
Legal basis: § 25(2) TTDSG (strictly necessary) as well as Article 6(1)(b) GDPR (performance of a contract).
(2) The Provider uses no tracking, analytics or marketing cookies. Should optional cookies be used in future, this shall be done exclusively following prior express consent within the meaning of § 25(1) TTDSG; in that case, a corresponding cookie setting shall be provided through which consent may be revoked at any time.
10. Payment Processing
(1) For the processing of paid Plans, we use the payment service provider Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands.
(2) We transmit to the payment service provider exclusively the information required to carry out the payment: the payment amount together with the currency, the invoice number as the payment reference, and pseudonymous reference identifiers of your contract. Your name, your e-mail address, your billing address and your value-added tax identification number are not transmitted to the payment service provider.
(3) The payment method is selected during the payment process. Credit card, SEPA direct debit and PayPal are available. The entry of the payment instrument data — in particular card and bank account details — takes place directly with the payment service provider or with the provider of the selected payment method. This data never becomes known to us; we receive only a notification of the status of the payment as well as the designation of the payment method used, which we store for accounting and invoicing purposes.
(4) If you select PayPal, the payment is processed via PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg. The payment service provider and the provider of the selected payment method process the data collected by them under their own responsibility, in particular in order to fulfil their own supervisory and anti-money-laundering obligations, on the basis of their respectively applicable privacy policies. We have no influence on the scope and purpose of this processing.
(5) A transfer of personal data by us to third countries outside the European Economic Area does not take place in the context of payment processing. Where PayPal is used, a transfer to undertakings affiliated with that provider outside the European Economic Area may take place; such transfer occurs under the responsibility of the provider on the basis of the safeguards established by it within the meaning of Articles 44 et seq. GDPR.
Legal basis: Article 6(1)(b) GDPR (performance of a contract).
11. Processing on Behalf and Recipients
(1) Personal data is transmitted exclusively to the following categories of recipients:
- IT service providers (hosting, database operation, backup) — in particular Hetzner Online GmbH, Gunzenhausen — on the basis of data processing agreements pursuant to Article 28 GDPR;
- payment service providers — Mollie B.V., Amsterdam; see Section 10;
- authorities and courts, insofar as there is a statutory obligation to transmit;
- out-of-court dispute resolution bodies, insofar as proceedings have been initiated.
(2) All processors are contractually obliged under Article 28 GDPR to maintain confidentiality, to implement technical and organisational security measures and to comply with further data protection obligations.
12. Hosting and Transfer of Data to Third Countries
(1) The platform is operated on servers of Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. The hosting service provider processes the personal data arising on the platform exclusively on our instructions as a processor on the basis of an agreement pursuant to Article 28 GDPR, including the technical and organisational measures agreed therein. The provider is certified in accordance with ISO/IEC 27001:2022 and holds an attestation under the C5 criteria catalogue (Type 2) of the German Federal Office for Information Security. The data centres used are located exclusively within the European Economic Area; processing outside the European Economic Area does not take place in the context of hosting. We will provide the specific place of processing on request in text form.
(2) A transfer of personal data to third countries outside the European Economic Area takes place exclusively
- on the basis of an adequacy decision of the European Commission within the meaning of Article 45 GDPR, or
- on the basis of appropriate safeguards within the meaning of Article 46 GDPR — in particular standard contractual clauses in their respectively current version.
(3) A transfer to third countries may arise in particular from OAuth registration via Google, Microsoft or Apple (see Section 5 paragraph 2).
13. Storage Period
Personal data is deleted as soon as the purpose of its processing ceases to apply and no statutory retention obligations — in particular under § 147 AO, § 257 HGB or § 14b UStG — preclude this. The storage periods stated in the preceding sections apply to the respective processing activities.
14. Your Rights as a Data Subject
You have — provided that the respective statutory requirements are met — the following rights vis-à-vis the controller:
- access to the data stored about you pursuant to Article 15 GDPR;
- rectification of inaccurate data or completion of incomplete data pursuant to Article 16 GDPR;
- erasure of your data stored with us pursuant to Article 17 GDPR;
- restriction of processing pursuant to Article 18 GDPR;
- data portability pursuant to Article 20 GDPR;
- objection to the processing pursuant to Article 21 GDPR;
- withdrawal of a consent granted pursuant to Article 7(3) GDPR — with effect for the future.
To exercise these rights, please contact: info@mcgesund.de.
15. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR regarding the processing of your personal data — in particular with the supervisory authority at the place of your habitual residence, your place of work or the place of the alleged infringement.
The supervisory authority responsible for the Provider will be disclosed on request.
16. AI-Supported and Automated Processing
(1) The Provider employs — insofar as described below — automated and AI-supported procedures. All procedures exclusively transcribe, translate, aggregate or generate; none makes an automated decision within the meaning of Article 22 GDPR with legal effect or similarly significant impact on the data subject.
a) Machine speech recognition in the "Signals" Module
Authorised employees of the business customer may capture status and completion notifications for tasks by voice. The audio data is automatically converted into text via a processor and deleted without undue delay after successful transcription. No voice profiles are created; identification of the speaker on the basis of the audio data does not take place. The business customer instructs its staff not to name any identifying data of third parties (real names, dates of birth, diagnoses) when dictating.
Legal basis: Article 6(1)(b) GDPR (performance of a contract vis-à-vis the business customer) and — insofar as personal data of the speaker is affected — Article 28 GDPR.
b) Machine translation
Content of public company profiles as well as editorial platform texts may be automatically displayed multilingually. For this purpose, we commission machine translation services established in the European Union. No transfer to a third country takes place in this regard; we shall disclose the specific provider on request in text form (see paragraph 2).
Legal basis: Article 6(1)(b) GDPR (performance of a contract).
c) Statistical and AI-supported analyses
Statistical and AI-supported analyses may be provided on the data captured in the "Signals" Module — for example capture density per location, distribution across categories or temporal trends. The analyses are carried out exclusively at aggregated level with a technical minimum aggregation value that excludes conclusions about individual persons. A personal performance or behaviour evaluation of employees does not take place.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in product improvement and aggregated analysis).
d) Conversational assistant (chatbot)
The platform provides a RAG-supported (retrieval-augmented generation) conversational assistant operated by the Provider itself. The underlying language model is operated on the Provider's own servers within the European Union; a transmission of your inputs to external language model providers does not take place.
In the retrieval stage, the assistant currently accesses exclusively public platform content (help articles, FAQs). For logged-in business customers, it may additionally access the data associated with the user account and the respective session — for example the booked Plan or reviews received for the customer's own location. Access to data of other business customers does not take place.
Before the start of each interaction, you are informed pursuant to Article 50(1) of Regulation (EU) 2024/1689 that you are interacting with an AI system.
Legal basis: Article 6(1)(b) GDPR (performance of a contract) as well as (f) (legitimate interest in user support).
e) AI-supported ranking optimisation and processing of search queries
The Provider reserves the right to additionally support the ranking of platform listings in future by means of a machine learning model trained on search queries and the click behaviour of platform users. Exclusively a model operated by the Provider itself on its own servers within the European Union shall be deployed. A linking of the training data with the user account, the IP address or other directly identifying features does not take place in the training and inference process; exclusively aggregated or pseudonymised signals are processed (in particular search term, category selected, result clicked, session identifier with limited lifetime).
The material main parameters of the ranking and their relative weighting are disclosed on the platform's ranking transparency page. Before a learning model is commissioned, you will be separately informed in this Privacy Policy as well as via the platform.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in relevant search quality for users and business customers).
f) Voice input in search
The Platform's search bar can be operated either by keyboard or by voice. Voice input is active only after you have expressly pressed the microphone button and your browser has obtained microphone permission; without both, no recording takes place. Keyboard input remains available and equivalent.
The recording is transmitted to a server of the Provider within the European Union, converted into text automatically there and discarded immediately after conversion. The audio data are not stored on any storage medium, nor are they transmitted to third parties or to external speech recognition services. The speech recognition model used is operated on the Provider's own servers.
No voice profiles are created. The audio data are not processed for the purpose of uniquely identifying a natural person; they therefore do not constitute biometric data within the meaning of Article 9(1) GDPR (compare Recital 51 GDPR).
The text obtained from the recording is treated like a typed search query and is subject to the same rules, in particular those described under point (e). In order to distinguish the origin of the query, it is technically recorded that the query was captured by voice; this record contains no personal details and serves solely to evaluate the two input methods separately.
The duration of microphone access is technically limited; the recording ends automatically. The recognised text is executed as a search query immediately and is displayed in the search field on the results page, where you can review and amend it.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in a low-barrier and convenient search function, the processing of which you trigger by your own action). For access to the microphone as terminal equipment: § 25(2) no. 2 TDDDG (formerly TTDSG), as the access is strictly necessary for the service expressly requested by you.
(2) A list of the processors employed will be provided on request in text form.
17. Automated Decision-Making
Automated decision-making, including profiling, within the meaning of Article 22 GDPR with legal effect or similarly significant impact on you does not take place. The AI-supported procedures described in Section 16 do not constitute any such decision-making.
18. Security of Processing
We employ technical and organisational measures pursuant to Article 32 GDPR to protect your data against accidental or unlawful processing, loss or alteration — in particular
- exclusively TLS-encrypted data transmission (HTTPS);
- storage of passwords as a salted cryptographic fingerprint (Argon2 or bcrypt);
- a role-based authorisation concept with "least privilege" on the Provider's side;
- regular security updates and pentest reviews.
19. Pre-Created Company Directory Listings and Take-over
(1) The Platform's company directory contains listings that the Provider has created in an automated manner in advance from publicly available sources — in particular the OpenStreetMap project under the Open Database License (ODbL) — without any contractual relationship existing with the company depicted at the time of creation.
(2) Only publicly available business data is taken over: company name, address, geocoordinates, category and — insofar as published in the source database — telephone number, website and opening hours. Personal data — in particular the real name of a sole proprietor — is taken over only if it is already publicly associated with the business activity in the source database.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in a comprehensive directory representation; counterpart to the classic public trade directory).
(3) We inform about the processing within the meaning of Article 14 GDPR by means of this Privacy Policy, by a source attribution pursuant to ODbL in the footer of the platform, as well as individually on request in text form.
(4) The company depicted in the listing may claim the listing for itself at any time via the "Take over Listing" function; upon Take-over, it enters into the maintenance of the listing as a contractual partner. As long as the listing has not been taken over, the company depicted may request the correction or deletion of the listing pursuant to Article 16 or Article 17 GDPR. Please direct requests to info@mcgesund.de.
20. Applications for Job Offers
Through the job offers published on McGesund, you can apply directly to the advertising company. When you submit the application form, we process the data you provide as follows:
Data processed: first name, surname, email address, telephone number (if provided) and the content of your message. Please do not include any special categories of personal data in your message (e.g. information on health, religion or trade-union membership).
Purpose: delivery and handling of your application by the advertising company, as well as the technical processing via our platform.
Transfer to the company: your application data is transmitted to the respective advertising company (the relevant company entry) — by email to the address provided by the company and by making it available in its McGesund account. The advertising company is an independent controller within the meaning of the GDPR for the further processing of your application; to that extent, the respective company's privacy notices apply. McGesund acts as an intermediary.
Legal basis: the performance of pre-contractual measures or the initiation of an employment relationship (Art. 6(1)(b) GDPR, § 26 Abs. 1 BDSG) as well as the consent you give in the form (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future.
Storage period: we store your application data only for as long as is necessary for delivery and proof, and delete it thereafter, unless statutory retention obligations require otherwise. The storage period at the company is governed by its own requirements.
Your rights: access, rectification, erasure, restriction, data portability and objection. In relation to the advertising company, please contact it directly; for the data stored at McGesund, please use the contact details set out in the "Provider" section.
21. Amendments to This Privacy Policy
We reserve the right to adapt this Privacy Policy to changed legal or factual circumstances. The respectively current version is available on the platform. We will additionally notify registered business customers of material changes by email.
Provider
Organon Informationssysteme GmbH
Karlstraße 31
63571 Gelnhausen
Data Protection Contact
info@mcgesund.de · Tel. +49 (0) 69 9043 1680
gültig ab 28.04.2026