Last updated: September 2026 — Thai Clinic App, Bruck Software GmbH
This translation is provided for convenience. The German version of this privacy policy is the legally binding one.
Introduction
Data protection is a high priority for Bruck Software GmbH. This website can generally be used without providing personal data. Personal data is only processed where necessary and with the data subject's consent.
1. Definitions
This policy is based on the terms of the General Data Protection Regulation (GDPR):
- Personal data — information about identified or identifiable persons
- Data subject — the person whose data is processed
- Processing — any operation on personal data (collection, storage, erasure, etc.)
- Controller — the person/organisation deciding on purposes and means of processing
- Processor — processes data on behalf of the controller
- Consent — freely given, informed agreement to data processing
2. Controller contact details
Grünewaldweg 17
73033 Göppingen
Deutschland
Tel.: 015750122548
3. Cookies and consent
This website sets no cookies without your consent. Statistics cookies (Google Analytics) are only set if you choose “Accept” in the cookie banner; with “Decline” or no decision, no cookies are set and no analytics services are loaded. Your choice is stored locally in your browser (localStorage) and can be changed or withdrawn at any time via the “Cookie settings” link at the bottom of the page.
The application itself (after signing in) uses technically necessary session cookies (legal basis: § 25 (2) TTDSG, Art. 6 (1) (b) GDPR).
4. Collection of general data
The website automatically records: browser type and operating system, referrer, visited pages, date and time of access, IP address and the internet service provider. This data serves security, optimisation and prosecution of cyber attacks.
5. Registration
Upon registration, the entered data is stored for internal use and abuse prevention, together with IP address, date and time. Users can have their data changed or deleted at any time.
6. Contact
When you contact us by e-mail, the transmitted data is stored to process the enquiry. It is not passed on to third parties.
7. Erasure and blocking
Personal data is stored only as long as necessary. After statutory retention periods expire, it is erased or blocked.
8. Rights of the data subject
You have the following rights: confirmation and access to stored data; rectification of inaccurate data; erasure, unless retention obligations apply; restriction of processing; data portability in a structured, machine-readable format; objection to processing, in particular for direct marketing; and withdrawal of any consent at any time. No one is subject to solely automated decisions with legal effect.
9. Google Analytics (only with consent)
We use Google Analytics only if you have previously consented via the cookie banner (Art. 6 (1) (a) GDPR, § 25 (1) TTDSG). Without consent the service is not loaded and no data is transmitted to Google. You can withdraw your consent at any time via “Cookie settings” at the bottom of the page.
Operator: Google Ireland Limited, Dublin. Data may be transferred to the USA (Google LLC); Google is certified under the EU-US Data Privacy Framework.
10. Payment processing via Stripe
For paid subscriptions we use the payment provider Stripe (Stripe Payments Europe, Ltd., Dublin). Processed data: name, e-mail address, billing address, VAT ID where applicable, and payment data; card data is collected exclusively by Stripe and never reaches our systems. Legal bases: Art. 6 (1) (b) and (c) GDPR.
Data may be transferred to Stripe, Inc. (USA); Stripe is certified under the EU-US Data Privacy Framework. More information: stripe.com/privacy.
11. Web fonts and e-mail delivery
Fonts are served locally from our own servers; no data is transmitted to Google font servers.
Transactional e-mails (e.g. registration and booking confirmations) are sent via carefully selected processors within the meaning of Art. 28 GDPR.
12. Legal bases and storage period
Processing is based on Art. 6 (1) (a) (consent), (b) (performance of contract), (c) (legal obligation) and (f) (legitimate interests — our business operations) GDPR. Data is stored according to statutory retention periods and then erased. Some data is legally or contractually required; failure to provide it may prevent a contract from being concluded. No automated decision-making or profiling takes place.