Privacy Policy

Last updated: September 2026

Data Controller

Responsible for data processing on this website is:

Lindotech GmbH
Eppendorfer Weg 151
20253 Hamburg
Deutschland
E-Mail: privacy@medishift.de
Website: www.medishift.de

Data Processing

Website Usage

When using our website, technical data such as IP address, browser type, operating system and access time are automatically collected. This data is used for the technical provision and security of the website.

SaaS Service

When using our SaaS platform, data is processed that is necessary for the provision of the service. This includes user accounts, work data and usage statistics.

Contact

When contacting us via email or contact form, the transmitted data is stored and processed to handle your request.

Legal Basis for Data Processing

• Contract fulfillment: To fulfill our contractual obligations

• Legitimate interest: To improve our services and security

• Consent: When voluntarily agreeing to data processing

Categories of Processed Data

Master Data

Name, email address, company name, address and contact details for account creation and contract processing.

Usage Data

Information about the use of our platform, including login times, used functions and created content.

Technical Data

IP addresses, device information, browser data and log files for technical provision and security.

Data Sharing

Data Processors

We use the following service providers as data processors:

  • Vercel Inc., website hosting and delivery (Server location: Germany, EU-US Data Privacy Framework certified)
  • Supabase Inc., database and authentication (Server location: Germany)
  • PostHog Inc., reach and usage analytics for improving the website (EU data center, eu.i.posthog.com)

All data processors are contractually obligated to comply with GDPR. Reach measurement with PostHog is cookieless: no cookies are set, no data is read from your device, and no personal profiles are created. The identifier is computed server-side from IP address, browser string and a salt that changes daily; that salt is deleted at the end of the day, so recognizing you beyond a single day is impossible. The legal basis is our legitimate interest in designing the website to meet user needs (Art. 6(1)(f) GDPR). You may object to this processing at any time with effect for the future (Art. 21 GDPR), via the “Opt out of analytics” link in the footer.

Authorities

Data is only shared with authorities if required by law or court order.

Google Ads conversion measurement

Purpose of the measurement

We run ads on the Google Search Network. So that we can tell which ad and which search term actually lead to a sign-up or a booked demo, Google assigns a click identifier (Google Click Identifier, GCLID; on Apple devices the equivalent identifiers “gbraid” or “wbraid” take its place) to every ad click and appends it as a parameter to the address you open. If a sign-up or a demo booking follows later, we report that identifier back to Google together with the time of the event. Without that report we would only know that someone clicked, not which ad was worth its price.

What is transmitted

Exactly five items are sent back: the click identifier Google issued in the first place, the name of the event (sign-up or demo booking), the time it happened, a calculated value with which we weight the two events, and the currency of that value (euros). We transmit neither your name nor your email address, neither your IP address nor a device identifier. The click identifier is not stored on your device: no cookies are set, no local storage is written, and nothing is read from your device. It is held in memory for the duration of your visit only and passed on to the page where the sign-up or the booking takes place.

Legal basis and your right to object

The click identifier is pseudonymous personal data: Google can link it to a person, we cannot. The legal basis for the processing is our legitimate interest in measuring the success of our advertising under Art. 6(1)(f) GDPR. Consent under Sec. 25(1) TDDDG is not required, because no information is stored on or read from your device. You may object to this processing at any time with effect for the future (Art. 21 GDPR). A plain message to datenschutz@medishift.de is enough; we will then report no conversion to Google for your click. If you would rather it never got that far, open our website directly at www.medishift.de instead of going through the ad: then no click identifier is passed on in the first place.

Recipient and retention

The recipient of the reported data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google is an independent controller for this processing and uses the data to attribute the conversion to the ad click, to steer bidding, and to produce statistical projections. A transfer to Google LLC in the United States cannot be ruled out; it is based on the European Commission adequacy decision on the EU-US Data Privacy Framework. If you book a demo, we attach the click identifier to the appointment in our calendar as an invisible property, where it is kept for as long as the appointment itself. Google accepts click conversions for at most 90 days after the click; after that the identifier is worthless for measurement.

Data Retention

Data is only stored for as long as necessary to fulfill the stated purposes or legal retention periods exist. Customer accounts are deleted after the end of the contract, unless legal retention obligations exist.

Your Rights

• Access: You have the right to information about the data stored about you

• Correction: You can request the correction of incorrect data

• Deletion: You can request the deletion of your data

• Restriction: You can request the restriction of data processing

• Portability: You can receive your data in a structured format

• Objection: You can object to data processing

• Complaint: You have the right to lodge a complaint with a supervisory authority

Supervisory Authority

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the competent supervisory authority:

The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany
E-Mail: mailbox@datenschutz.hamburg.de
Website: https://datenschutz-hamburg.de

You may also contact the supervisory authority of the member state where you reside or work (Art. 77 GDPR).

Data Security

We implement technical and organizational security measures to protect your data against manipulation, loss, destruction or unauthorized access. Our security measures are continuously improved in line with technical developments.

Cookies

Since August 2026 we no longer set cookies for reach and usage analysis, nor do we read any data from your device; Sec. 25(1) TDDDG does not apply to it and no consent is obtained. Only the bare minimum is stored in your browser: your language preference and, if you have objected, your objection to the analysis. Both deliver a service you explicitly requested and are therefore exempt from consent under Sec. 25(2) no. 2 TDDDG. Details on the analysis and on your right to object under Art. 21 GDPR can be found in the “Data Processors” section. Measuring the success of our Google ads also works without cookies; see the section “Google Ads conversion measurement” for details.

Privacy Policy Updates

This privacy policy is updated when data processing changes. We recommend checking it regularly. You will be informed of significant changes.