Privacy policy
This translation is for information. The German version at /datenschutz is the binding one.
Not yet reviewed by a lawyer
This text is complete but has not yet been reviewed by a lawyer (T4 in SPEC §2.4). After the review Impflotse replaces it with the reviewed version.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is the operator of Impflotse:
Alexander Seipel
Jeseniova 2829/20
130 00 Praha 3
Tschechische Republik
E-mail: hallo@impflotse.de
We have not appointed a data protection officer: the conditions of Art. 37(1) GDPR are not met, because this service processes health data neither on a large scale nor as the core activity of a large organisation. Questions about data protection are answered at the address above.
2. What data we process
Appointment booking
Salutation, first and last name, e-mail address, phone number, the vaccination chosen, the appointment and the pharmacy. The pharmacy needs the phone number for cancellations at short notice. Along with that, the language you booked in — so that the reminder and any cancellation reach you in the same one.
The legal basis is Art. 6(1)(b) GDPR: we arrange the appointment for you, and that contract cannot be performed without these details. For the vaccination chosen, Art. 9(2)(a) GDPR applies in addition (section 3). These fields are therefore mandatory — without them the booking does not go through. No law obliges you to provide anything.
Name, e-mail address and phone number are held by us in encrypted form. Anyone who gets hold of the database, or of a backup of it, reads no name there. Your address can only be found again through a key value computed from it — it answers “the same address” without answering “which address”.
You enter your date of birth in the form so that we can check the minimum age for the vaccination chosen. We do not store it: the check runs when you submit, the date is discarded afterwards and appears in no record. Your ID is checked by the pharmacy on site.
After the appointment the pharmacy records whether you turned up. That is part of the documentation § 22 IfSG requires of it, and it is the only entry that outlives anonymisation — what is counted afterwards is an appointment, not a person.
Medical questions before the appointment
Before you submit, you can answer six questions with yes or no that the pharmacy would ask at the counter anyway: acute illness, known allergies to vaccine components, unusual reactions to earlier vaccinations, a weakened immune system, blood-thinning medication, pregnancy or breastfeeding. There is no free-text field.
Answering is voluntary. You can leave any question open or skip the step entirely; the booking is complete either way, and a question left open stays distinguishable from a “no” as “not answered”.
The answers are seen by only the pharmacy you booked with. They appear in no list, no search and no e-mail, they are held encrypted, every access to them is logged, and they are deleted when the booking is anonymised. On what basis we process them is in section 3.
Appointment requests to pharmacies that are not connected
First and last name, e-mail address, optionally a phone number, gender, age, the vaccination requested, a preferred date and the language of the request. We pass these details on to the pharmacy you chose.
The legal basis is Art. 6(1)(b) GDPR — the request is the step before an appointment, and you trigger it yourself — and for the vaccination requested your consent under Art. 9(2)(a) GDPR in addition.
Enquiries from pharmacies
If you use the form for pharmacies: the name of the pharmacy, street, postcode and city, contact person, e-mail address, phone number and your message. The purpose is initiating and performing a contract with the pharmacy (Art. 6(1)(b) and (f) GDPR).
Messages through the contact form
Your name, e-mail address, your message and the language you were reading the site in — the last one so that the answer comes back in it. The legal basis is Art. 6(1)(f) GDPR: someone who writes to us expects an answer. Where the message concerns a contract with us, it is Art. 6(1)(b) GDPR.
The message goes into our mailbox and into no database. Please do not write to us about your health: the form does not ask for it, and the pharmacy is the right place for anything to do with the appointment.
A pharmacy registering itself
A pharmacy can register itself. In doing so we process the name and address of the pharmacy, the phone number, the e-mail address the confirmation link goes to, the contact person, and which version of our terms was accepted and when. The legal basis is Art. 6(1)(b) GDPR.
If the pharmacy is already on our list, the link goes to the address held there and never to a freshly typed one: a registration can therefore only be completed by someone who reads the pharmacy’s own mailbox. Where the address is typed in by hand, we have it geocoded once (MapTiler, section 5). How often one address has requested such a link is counted, so that the picker cannot be used as a relay for unwanted mail (Art. 6(1)(f) GDPR).
Pharmacies we approach
For our sales work we keep a list of Berlin pharmacies compiled from publicly available directories: name, address, phone number and the business e-mail address. To that we add what comes out of the contact — the name of the contact person, notes on the conversation, follow-up reminders and where the cooperation stands.
This is data about people in their professional role; the legal basis is our legitimate interest in initiating that cooperation (Art. 6(1)(f) GDPR). You may object to it under Art. 21 GDPR without any formality — we then delete the notes and keep only the record that no contact is wanted.
Access to the pharmacy portal
A portal account carries the business e-mail address and the password as a check value, never in clear text. Where a passkey has been set up, its public key, its identifier and the label chosen for it are added. A passkey contains no biometric data: your fingerprint or face is checked by your device on the device, and all we are sent is a signature.
Server logs
When pages are requested, our web server logs the IP address, the time, the address requested, the response status and the browser identification. This is necessary to operate the service and to fend off attacks (Art. 6(1)(f) GDPR).
Before writing, we remove from the requested address whatever is sensitive: the single-use links from our e-mails — the cancellation link, the password link, the invitation, the confirmation link of a registration and the address of a calendar subscription — and every search query. The postcode or street you type into the search appears in no log line. Cookies, credentials and the previously visited page are not logged at all.
These logs have no deadline in days but a fixed size: the web server keeps seven files of 20 MB each, the application logs three of 10 MB each per service. What falls out of that ring is deleted — how long that takes depends on traffic. The application logs contain neither names nor e-mail addresses: who we sent a message to appears there only as a pseudonym that changes on every restart and cannot be resolved against anything.
Login attempts and blocks
So that nobody can work through passwords or use our forms as a relay for unwanted mail, we count attempts per sending address. The counters do not carry the IP address itself but a value computed from it — which keeps the table, and every backup of it, free of readable addresses.
Failed logins to the pharmacy portal are the exception: they are stored in the database with the IP address and the e-mail address, because the block has to tell the two apart. Those rows are deleted after 15 minutes, and immediately on a successful login. The legal basis is Art. 6(1)(f) GDPR, and additionally Art. 32 GDPR.
Audit log (changes and access)
Separately from that we keep a log of who changed, deleted or viewed which record and when, and who logged in and out. This is a security measure we are required to take (Art. 5(2) and Art. 32 GDPR): without it, unauthorised access to your data could be neither detected nor reported to you. The legal basis is Art. 6(1)(c) GDPR, and additionally (f) for fending off attacks.
An entry contains the time, the account or role of the person acting, the type of action and the identifier of the record concerned — for changes, additionally the names of the fields changed. It contains no content: no names, no contact details, not the vaccination chosen, and not the values before or after a change. For login events the IP address is stored as well.
The log is checked against fixed thresholds — a series of failed logins, say, or an unusually large read — so that an attack stands out without anyone reading every line. It is checked only against those fixed values, never against the past behaviour of individual accounts; no decision about you is made in the process. When a rule triggers, a message goes to our operations; it names the number of anomalies and expressly not who caused them.
Entries are deleted automatically after 365 days, the IP address already after 90 days. Entries cannot be changed afterwards — that is the purpose of such a log. We may therefore refuse an erasure request under Art. 17 GDPR for these entries until that period expires (Art. 17(3)(b) and (e) GDPR); your right of access under Art. 15 GDPR does cover them.
3. Health-related data (Art. 9 GDPR)
Two things in this service are health data: the vaccination chosen, which allows conclusions about your health, and — if you answer them — the medical questions before the appointment. We process this special category of personal data exclusively on the basis of your explicit consent under Art. 9(2)(a) GDPR.
There are two separate consents, each with its own checkbox: one for handling the appointment including the vaccination chosen, one for the medical questions. You can leave the second out without losing the first — the booking is then made without those answers. For both we store the time and the version of the text you agreed to (Art. 7(1) GDPR).
You can withdraw either consent at any time with effect for the future, for example by cancelling the appointment through the link in your confirmation e-mail or by writing to us.
4. Minors
Vaccination at a pharmacy is only possible from the age of 18. Anyone younger can neither book an appointment nor send an appointment request through Impflotse — the form rejects the entry. Why we need the date of birth for that and why we do not store it is in section 2.
5. Recipients
The pharmacy you book with receives your data in order to carry out the vaccination. For everything it does with that data afterwards — advice, vaccination, its own documentation — it is itself the controller within the meaning of Art. 4(7) GDPR.
On request we additionally make the day’s appointments available to it as a calendar subscription: an address its calendar program fetches on its own, containing the time, your name, your phone number and the vaccination. Which program that is, is the pharmacy’s decision; if it uses a calendar service on the internet, those details go there, and the pharmacy is responsible for that. The address can only be fetched from us, is listed in no directory, and can be invalidated by the pharmacy at any time.
Alongside that we use the following service providers (processing on our behalf under Art. 28 GDPR unless stated otherwise):
- Hetzner — server operation in the Falkenstein data centre (Germany) and encrypted backups on a storage box. All the data named above is held there.
- Brevo — sending our e-mails: confirmation code, appointment confirmation, reminder, cancellation and appointment request to the pharmacy, along with the messages around a pharmacy’s registration and access. The e-mail address, the name and the content of the message are transmitted.
- MapTiler — map tiles and address search. When the map view is opened your browser transmits your IP address to MapTiler; for the address search we additionally transmit the search text you entered from our server, without your IP address.
- Porkbun — domain management and forwarding of our mailboxes. Replies you send to our addresses go through this provider.
- Sentry — error monitoring, stored in the EU region. Only what our server has filtered beforehand is reported: the kind of error, the stack trace, the service affected and the identifier of a record concerned. The request, headers, cookies, form contents and your IP address do not go with it; the text of a database error message is withheld, because it quotes the data the error occurred on.
6. Transfers to third countries
Servers and backups are located in Germany. Three points nevertheless lead out of the EU:
- Porkbun is based in the United States. Every e-mail you send to one of our addresses passes through the forwarding there.
- MapTiler is based in Switzerland. When the map loads, the connection may also run through delivery servers outside Switzerland and the EU.
- Sentry stores our error reports in the EU region. The operator is based in the United States and can access them from there.
For Switzerland the European Commission has found the level of data protection adequate (Art. 45 GDPR); that transfer needs no further safeguard. If a map request runs through a delivery server outside Switzerland and the EU, the European Commission’s standard contractual clauses apply (Art. 46(2)(c) GDPR).
For the two providers based in the United States — the forwarding of our mailboxes and the error monitoring — we likewise rely on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).
Where a calendar subscription leads is decided by the pharmacy alone. If it picks a calendar service outside the EU, that transfer is its own and not ours.
7. Retention
- Appointment bookings: 90 days after the appointment, salutation, name, e-mail address, phone number and the medical answers are removed, the key value for the address goes with the address, and the time is coarsened to the month. What remains is a record without a personal reference — vaccination, month, pharmacy and whether the appointment was kept — which the pharmacy needs for its accounting.
- Appointment requests: deleted after 90 days.
- Enquiries from pharmacies: deleted after 365 days.
- Messages through the contact form: they exist only in our mailbox. We delete them there once the matter is settled — by hand, because there is no database row for a nightly run to find.
- Self-registrations: for as long as the pharmacy is on our books — the row is the evidence of which version of the terms was accepted and when, and it is deleted with the pharmacy. A registration whose confirmation link was never used is deleted in full once the link expires: it is valid for 48 hours, and the deletion runs the night after.
- Pharmacy portal credentials and passkeys: for the duration of the cooperation.
- Failed logins: 15 minutes, and immediately on a successful login.
- Pharmacies we approach: as long as the contact or the cooperation lasts; after an objection only the record that no contact is wanted remains.
- Audit log: 365 days; the IP addresses it contains already after 90 days.
- Backups: our encrypted backups expire on a staggered schedule and therefore contain states up to seven months old — including data that has already been anonymised or deleted in normal operation. An erasure on request takes effect on the live data, not retroactively in the backups; those expire by themselves.
Statutory retention obligations remain unaffected. They concern the commercial side of our cooperation with pharmacies — invoices and receipts — not your appointment booking: no payment runs through Impflotse, and your booking is not a receipt within the meaning of those provisions.
8. Maps, cookies and audience measurement
We use only technically necessary cookies and embed neither trackers nor external fonts. That is why no cookie banner appears: no cookie is set before a login, and the map library stores nothing on your device — the consent requirement of Art. 5(3) of the ePrivacy Directive and its national implementations therefore does not apply.
One exception belongs here explicitly: we load the map tiles from MapTiler. As soon as a page with a map is opened — so before any input — MapTiler learns your IP address and which map section you are looking at. The basis is our legitimate interest in a usable proximity search (Art. 6(1)(f) GDPR). Every other part of the page — including the map software itself — is delivered from our own server.
We do count how often our pages are opened — to see whether this service is found and used at all, and in which districts people search without finding a pharmacy. What is counted is page views, searches, unsuccessful searches and forms opened, each as a daily total.
What matters is how a page is named in the process: as a pattern (“a pharmacy page”, “a booking form”), not as the address you opened. What you type into the search, and the personal links from our e-mails, do not appear in this count. No cookie is created, nothing is stored on your device, there is no visitor identifier and no stored IP address; nobody can read from it which pages one person opened one after another. That, too, is why no banner appears: nothing is read from or written to your device for it.
What is stored in the end is one number per day and event. These numbers are anonymous: they cannot be attributed to a person — not even by us. An objection under Art. 21 GDPR therefore has nothing to attach to, because there is no record about you it could refer to. The legal basis for the counting itself is our legitimate interest in a working service (Art. 6(1)(f) GDPR). Pages behind a login — the areas for pharmacies and for ourselves — are not counted.
9. Automated decisions
Three things are decided automatically: the booking form rejects anyone below the age limit of the vaccination chosen; after several failed attempts a portal login locks itself for 15 minutes; and a form submitted too often from the same sender address is refused. All three compare a single entry against a fixed value.
No profile of you is built in the process, your earlier behaviour is not drawn on, and the decision is taken afresh every time. We take no automated decision in an individual case within the meaning of Art. 22(1) GDPR — one producing legal effects concerning you or similarly significantly affecting you.
10. Your rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and a complaint to a supervisory authority (Art. 77). The authority responsible for us is the Office for Personal Data Protection of the Czech Republic (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7). Under Art. 77(1) GDPR you may also turn to the supervisory authority of your own place of residence or work — for Berlin that is the Berlin Commissioner for Data Protection and Freedom of Information.
Please address requests to the postal address given in the imprint; we reply within one month (Art. 12(3) GDPR). Please state the e-mail address you booked with — that is how Impflotse finds your data. For appointments further in the past, the booking number from your confirmation e-mail helps as well: anonymised bookings no longer carry an address and cannot otherwise be found.