Privacy Policy
Version 1.1 · As of 12 August 2026
Draft — legal review by a qualified lawyer is still pending. The content has been prepared carefully but has not yet been finally reviewed.
1. Controller
The controller within the meaning of the GDPR is:
BGGI GmbH Rostocker Straße 43 53117 Bonn Germany
E-mail: datenschutz@bggi.de
2. Categories of Data Processed
Master data: name, e-mail address, phone number, date of birth, nationality, address.
Health data (Art. 9 GDPR): medical documents you upload as well as case, appointment and treatment information.
Usage data: IP address, login timestamps, log data (tamper-proof audit log).
Billing data: cost estimates, invoices, payments.
3. Purposes of Processing
Coordination of international medical treatments (case management, clinic and doctor matching, appointment scheduling).
Account management and authentication, including optional two-factor authentication.
Billing and fulfilment of statutory retention obligations.
Security, error analysis and abuse prevention.
4. Legal Bases
Performance of a contract — Art. 6(1)(b) GDPR.
Explicit consent to the processing of health data — Art. 9(2)(a) GDPR.
Legal obligation (e.g. commercial and tax retention duties) — Art. 6(1)(c) GDPR.
Legitimate interest in the security of the platform — Art. 6(1)(f) GDPR.
5. Recipients
Treating hospitals and physicians only receive access to your case data after your case has been assigned, and only to the extent of the documents released by BGGI.
We use the following processors under Art. 28 GDPR: • Google Cloud EMEA Ltd. (Ireland) — hosting and database, data centre Frankfurt am Main (europe-west3), incl. Firebase Hosting as delivery layer. • Stripe Payments Europe Ltd. (Ireland) — payment processing; card data remains exclusively with Stripe. • Resend (USA) — sending and receiving transactional email (EU standard contractual clauses). • Daily.co (USA) — video consultations; media servers in the EU region (eu-central-1), no recording (EU standard contractual clauses). • Anthropic (USA) — AI-assisted pre-analysis of submitted documents, only with your separate consent; results are always reviewed by BGGI staff (EU standard contractual clauses). • Sentry (Functional Software, Inc., USA) — technical error diagnostics; personal and medical content is automatically removed or masked before transmission (EU standard contractual clauses).
Transfers to third countries outside the EU/EEA only take place where appropriate safeguards under Art. 44 et seq. GDPR exist (in particular EU standard contractual clauses) or where you have expressly consented (Art. 49(1)(a) GDPR).
6. Retention Periods
Account data: until your account is deleted or an erasure request has been completed.
Invoice and accounting data: 10 years pursuant to § 147 AO (German GoBD rules).
Audit logs: stored immutably and tamper-proof.
Case data and medical documents: for the duration of case handling and thereafter per the statutory retention obligations for treatment records (generally 10 years, analogous to § 630f German Civil Code); then deletion or anonymisation.
Communication with hospitals (email/portal): same as case data — it forms part of the case file.
Consent records: up to 3 years after revocation or account deletion (accountability, Art. 7(1) GDPR).
Server and security logs: maximum 90 days, unless a security incident requires longer retention.
Daily encrypted database backups: 30 days (daily states) and 12 months (monthly states), stored exclusively in the Frankfurt region.
7. Your Rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR).
You may withdraw any consent given at any time with effect for the future.
Data export and erasure requests are available directly in the portal under “Privacy”.
Right to lodge a complaint: State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
8. Data Security
TLS transport encryption, encryption of sensitive secrets (AES-256-GCM), Argon2id password hashing, optional two-factor authentication, role-based access control and a tamper-proof audit log — technical and organisational measures pursuant to Art. 32 GDPR.
9. Cookies
We use technically necessary cookies (login/session, security, language setting, storage of your cookie choice). These are required to operate the platform (§ 25 (2) TTDSG; Art. 6(1)(b) and (f) GDPR).
Optional cookies (e.g. statistics) are only set with your consent via the cookie banner (Art. 6(1)(a) GDPR). Your choice is valid for 12 months and can be changed at any time via “Cookie settings” in the footer. We currently do not use any statistics or marketing cookies.
10. Transfer to treating hospitals abroad
The platform's purpose is arranging medical treatment, predominantly in Germany. At your request, case data may also be transferred to treating hospitals or physicians outside the EU/EEA (e.g. in your home country).
Such transfers take place exclusively on the basis of your explicit consent (Art. 9(2)(a), Art. 49(1)(a) GDPR) and only to the extent of the documents you released. Third countries may not provide a level of data protection equivalent to the EU; we point this out before every transfer.
You can revoke your consent at any time with effect for the future (portal → privacy). Transfers already made remain unaffected.
Change history
- 2026-08-12 — Version 1.1 — processors specified, retention periods added, transfer to treating hospitals abroad, payment/cancellation/refund rules, new documents (withdrawal, telemedicine, health-data consent, cookies).
- 2026-08-08 — Version 1.0 — initial publication.