Staff Agreement on Confidentiality and System Use
Version 1.0 · As of: 8 September 2026
Draft — legal review by a qualified lawyer is still pending. The content has been prepared carefully but has not yet been finally reviewed.
1. Subject matter and relationship to the employment or service contract
This agreement is concluded between BGGI GmbH, Rostocker Straße 43, 53117 Bonn, HRB 26753 Amtsgericht Bonn (“BGGI”), and the staff member who accepts it digitally via the BGGI Health platform (“Staff Member”).
This agreement is NOT an employment contract. It governs neither remuneration nor working time as a service owed, neither holiday nor termination of the employment relationship. The employment or service contract is concluded outside the platform and remains unaffected by this agreement.
Its subject is solely confidentiality and the use of BGGI's systems.
2. Confidentiality
Staff members maintain silence about all matters that come to their knowledge. This applies to data of patients, to information from physicians, clinics, agencies and service providers, and to BGGI's business secrets and conditions.
The duty of confidentiality applies towards everyone, including family members, and continues without time limit after the end of the activity.
Statutory, professional and criminal-law duties of secrecy as well as statutory duties to provide information remain unaffected.
3. Handling of health data
Health data is specially protected data under Art. 9 GDPR. It is processed exclusively for handling the respective case and made accessible only to those persons who need it for their task.
Opening a record out of curiosity, out of personal interest or without reference to one's own task is prohibited — even where technical access would be possible. Accesses are logged.
Health data is not transferred to private devices, private storage or private mailboxes and is not printed out unless this is necessary for the task.
4. Role and area permissions
Staff members receive permissions only for the areas they need for their task, and only at the level required for it (view, edit, approve).
Permissions are not circumvented, not shared and not passed on to others. If it is noticed that a permission reaches further than the task requires, this is reported to the administration.
5. Mandatory two-factor authentication for administration accounts
For access to the administration area, the second factor is mandatory. It is set up via the route offered in the platform; without an activated second factor there is no entry.
The second factor is personal. Codes, recovery keys and devices are not passed on. The loss of a device or key is reported without delay.
6. Time tracking
The platform records the start, the end and interruptions of work as well as the type of the recorded segment. The purpose is compliance with the statutory recording obligations, billing and planning.
Time tracking does not serve to monitor performance or conduct. No covert observation takes place.
Staff members can view their own times at any time and may request a correction. Participation rights of the employee representation remain unaffected. [Placeholder — retention period and evaluation rules to be determined by the management]
7. Devices and access
Devices, access credentials and keys provided are kept carefully and used only for the task. Access credentials are personal and are not passed on.
Screens are locked when leaving the workplace. Access from open networks without a secured connection is prohibited.
Any suspicion of loss or unauthorised use of devices or access credentials is reported without delay.
8. Prohibition of private disclosure of patient data
Information about patients is not disclosed privately, not mentioned in private messaging services or social networks and not photographed or recorded.
Even accounts that appear anonymous can make a person identifiable; they are therefore likewise prohibited.
9. Duty to report a suspected data protection breach
Any suspicion of a personal data breach — lost documents, a wrongly addressed message, access by an unauthorised person, a lost device — is reported without delay to the administration and to the data protection officer.
The report is also made where the breach was caused by the reporting person themselves. A prompt report is not held against the reporting person; BGGI's statutory deadlines depend on it.
10. End of the activity
Upon the end of the activity, all devices, documents, data carriers and keys are handed over without delay; access is blocked and running sessions are ended.
Copies of company data are not retained. The duty of confidentiality under section 2 continues to apply.
11. Final provisions
The law of the Federal Republic of Germany applies. Should individual provisions be invalid, the remainder of the agreement remains effective.
Amendments require text form. The German version of this agreement prevails; translations are for information only.
Change history
- 2026-09-08 — Version 1.0 — initial version (draft pending legal review).