Privacy Policy
Last updated: 21 August 2026
1. Data Protection at a Glance
This privacy policy explains what happens to your data when you visit this website, when you get in touch with us and when you are a patient at our practice. We have deliberately written it so that you can understand it without any legal background. If any part of it is still unclear, please call us. We will explain it to you personally.
The key points in brief: you can look around this website and find out about us without telling us your name. When you open a page, our hosting provider automatically creates technical log data and deletes it shortly afterwards. We only set advertising and analytics cookies if you expressly agree in the consent banner. We only load the Google Maps map if you choose to load it yourself.
If you write to us, call us or send a message on WhatsApp, we process whatever you tell us. If it is about your symptoms, a course of treatment or a doctor's prescription, that counts as health data. Data of that kind is specially protected, and we are also bound by professional confidentiality.
You always have the right to ask what data we hold about you, to have it corrected or erased and to object to processing. You can withdraw any consent you give us at any time, informally, and it will never count against you. Your treatment never depends on whether you agree to advertising cookies. How to exercise these rights is explained further down, in the sections "Your Rights" and "Right to Lodge a Complaint with the Supervisory Authority".
2. Controller
The controller for the data processing on this website and at the practice is:
Anker Physio und Therapie GmbH Trading as Physio+Therapie represented by the managing director Diana Woyzek, state-recognised physiotherapist Kaiser-Friedrich-Straße 79 10585 Berlin
Telephone: 030 488 148 59 Email: info@physioplustherapie.com
The controller (Verantwortliche Stelle) is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data. In plain terms: we decide which data is processed and what for, and we are your point of contact for any questions about it.
If you have a question about your data, want to withdraw consent or want us to erase something, please use the contact details above. You can reach us by phone on Monday from 08:00 to 17:30, Tuesday and Wednesday from 08:00 to 17:00, Thursday from 08:00 to 18:00, and Friday from 08:00 to 14:00. The practice is closed on Saturday and Sunday. There is no form to fill in and no particular wording you have to use. A phone call is enough.
3. Data Protection Officer
We have not appointed a data protection officer, because the law as it currently stands does not require us to. We will tell you openly why:
Under Section 38 (1) sentence 1 of the Bundesdatenschutzgesetz (German Federal Data Protection Act), a company only has to appoint a data protection officer if 20 or more people are normally engaged on an ongoing basis in the automated processing of personal data. Our practice is considerably smaller.
Under Article 37 (1) (c) of the General Data Protection Regulation, a further obligation applies regardless of headcount where the core activity consists of processing health data on a large scale. Recital 91 of the General Data Protection Regulation makes this explicit: the processing of patient data by an individual physician or other health care professional is not regarded as large scale. Our practice is run by a single physiotherapist and has only a few members of staff. On that basis, our processing is not large scale within the meaning of the provision.
Under Section 38 (1) sentence 2 of the Bundesdatenschutzgesetz (German Federal Data Protection Act), an appointment would also be required if we carried out processing that calls for a data protection impact assessment under Article 35 of the General Data Protection Regulation. We check every new processing operation against this and record the outcome. If that changes, for example because the practice grows or because we introduce more extensive digital appointment management, we will appoint a data protection officer and add the details here.
Until then, the person to ask about anything to do with data protection is our managing director Diana Woyzek, at info@physioplustherapie.com and 030 488 148 59.
4. Professional Confidentiality and the Special Protection of Your Health Data
As physiotherapists we are bound by professional confidentiality (Schweigepflicht) under Section 203 (1) no. 1 of the Strafgesetzbuch (German Criminal Code). Everything you tell us about your symptoms, your diagnosis, your treatment or your prescription stays inside the practice. We do not pass it on to anyone else unless you have expressly allowed it or a law requires us to.
Health data falls within the special categories of personal data under Article 9 of the General Data Protection Regulation. Stricter rules apply to it than to an ordinary name or address. We process your health data because it is necessary for your physiotherapy care and treatment, and because everyone at the practice who handles it is bound by professional confidentiality or has signed a written confidentiality undertaking with us.
In addition, we take appropriate and specific safeguards under Section 22 (2) of the Bundesdatenschutzgesetz (German Federal Data Protection Act). These include: keeping treatment records in lockable storage, keeping screens and paperwork out of view of the waiting area, giving access only to people who need the data for their work, putting every member of staff under a written confidentiality obligation, training the team, and following clear rules on when data is deleted.
A quick word from us: please do not send us detailed medical information by email or messenger. For a first appointment request, all we need is your name, a number to call you back on, and a word about whether you have a prescription. We can discuss everything else on the phone or at the practice. That is safer for you.
5. Hosting of This Website and Server Log Files
The technical side of this website is run for us by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Vercel provides the servers and the content delivery network that bring the pages to your screen. Vercel acts solely on our instructions. We have a data processing agreement with Vercel under Article 28 of the General Data Protection Regulation.
When you open a page, your browser sends technically necessary information to those servers. What is recorded: the address you opened, the date and time of access, the browser type and version, the operating system you use, the page you visited before, if your browser passes it on, and your IP address. We need this so that the page can reach your device in the first place, and so that we can spot faults and attacks.
Vercel generates these logs automatically and deletes them automatically. Depending on the plan, they are kept for no longer than 30 days. We do not analyse these logs to identify individuals, we do not combine them with other data, and we do not build profiles from them.
Vercel is based in the USA. You can read more about transfers to the USA and the safeguards involved in the section "Data Transfers to the USA".
6. The Plus Jakarta Sans Typeface
We use the Plus Jakarta Sans typeface on this website so that the text is easy to read. The font files are not fetched from an outside server every time a page loads. They were downloaded once when the website was built and have been stored on our own server ever since.
What that means for you: when you open this page, your browser makes no connection to Google Fonts or to any other font service. Your IP address is not sent to Google as part of this.
7. The Contact Form on This Website
On the home page and on the Contact page you will find a form with the fields Name, Email, Mobile number and Message. Please read the next paragraph carefully, because this form works differently from the ones you know from other websites.
This form does not send anything to any server of ours. There is no form backend and no database behind it. When you click the button, your device opens your own email app and creates a ready-made email to us there, with your entries already filled in. The message only leaves your device once you send that email yourself from your own email app. Until you do, we know nothing about what you have typed.
So, to be clear: everything you type while filling in the form stays on your own device, in your browser, and is not sent to us. The message is sent by your own email provider, not by us. From your outbox onwards, your email provider's terms apply to the transmission. If there is no email app set up on your device, nothing happens when you click. In that case you can reach us by phone on 030 488 148 59.
Once your email reaches us, we handle it as described in the section "Contact by Email and by Telephone".
Two things we would ask: the ready-made message has lines for what your enquiry is about and for whether you have a prescription. You do not have to fill those lines in. For an appointment request, your name and a number to call you back on are enough for us. And please do not describe your symptoms to us at length by email; the phone or a conversation at the practice is better. An ordinary email is not encrypted all the way along its journey.
8. Contact by Email and by Telephone
If you send us an email at info@physioplustherapie.com or call us on 030 488 148 59, we process whatever you tell us. That is usually your name, a number or email address to reply to, what your enquiry is about, and the appointment time you would like. If you mention something about your symptoms or your prescription, health data is involved too.
We use this information only to deal with your enquiry and to arrange an appointment with you. We do not pass it on to anyone else. We do not send you advertising on this basis.
How long we keep it: if you do not go on to have treatment with us, we delete your email and our phone note no later than six months after our final reply. If you do become a patient, we transfer the information needed for your treatment into your patient record. We keep that for ten years after treatment ends, under Section 630f (3) of the Bürgerliches Gesetzbuch (German Civil Code), unless other rules require us to keep it longer. After that we destroy it securely, in line with data protection requirements.
Please bear in mind: an ordinary email is not encrypted all the way across the internet and could be read by others along the way. If you want to give us confidential health information, please call us or speak to us at the practice.
9. Contacting Us via WhatsApp
On every page of our website you will find a green WhatsApp button. It is an ordinary link to the address wa.me. Here is exactly what happens, so that you can decide for yourself.
As long as you do not click the button, nothing happens. No content is loaded from WhatsApp or Meta, and none of your data is sent to WhatsApp.
If you click the button, you leave our website. Your device opens the address wa.me and starts WhatsApp with a message to our practice number already drafted for you. At that moment, the operator of WhatsApp sees your IP address and the fact that a chat with our number is being opened. Whether you then actually send the message is up to you. You can also change the drafted text, or delete it entirely, before you send it.
The operator of the service for users in Europe is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. It is part of the Meta group. The contents of your messages are encrypted end to end, so WhatsApp cannot read them. WhatsApp does, however, process what is known as metadata as controller in its own right, for example your phone number, our phone number, the time and frequency of the communication, and device and connection data. This metadata may also be transferred to servers outside the European Union. We have no control over what WhatsApp does with it. WhatsApp's own privacy notice applies.
At our end, we treat your WhatsApp message like any other appointment request. We do this on a device that is used only at the practice. The app's access to that device's address book is switched off, so no one else's contact details are sent to WhatsApp. We copy the details we need for the appointment into our appointment book. We delete the chat history no later than three months after the conversation has ended.
In legal terms, we rely on the fact that you choose the channel yourself. You deliberately decide to message us on WhatsApp even though two protected alternatives are open to you. Your consent rests on exactly that choice.
If you would rather not, please use one of these instead: phone 030 488 148 59, email to info@physioplustherapie.com, or a conversation with us at the practice. It will not put you at any disadvantage, either when booking an appointment or during treatment. Please do not use WhatsApp to send us detailed medical information, test results or photographs of prescriptions or letters from doctors.
10. Booking Appointments and Our Appointment Book
When you book an appointment with us, we write down what we need for it in our appointment book: your name, a way for us to reach you at short notice if we need to ask something or cancel, the therapist who will treat you, the date and time, and a short note on the type of appointment, for example whether it is a first visit. We write down nothing more than that. Test results, diagnoses and detailed treatment histories in particular do not belong in the appointment book but in your patient record.
Our appointment book is currently kept on paper. During opening hours it sits at reception, positioned so that nobody in the waiting area can read it, and it is closed as soon as no one is working with it. Outside opening hours we keep it locked away. Only the people who need it for their work have access.
How long we keep it: entries in the appointment book are not part of your patient record, so they are not kept for ten years. We destroy the book securely, in line with data protection requirements, once the year in question is complete and the following quarter has ended. Anything that has to be documented for your treatment, for example a missed appointment or a break in treatment, goes into your patient record beforehand and is stored there under the rules that apply to it.
If we move to digital appointment management in future, we will tell you here before we do so and give the name and registered office of the company we engage. Alongside digital booking, you will always still be able to book an appointment with us by phone or in person.
11. Consent Banner and Google Consent Mode v2
The first time you visit this website, a banner appears where you can decide whether you consent to anything beyond the technically necessary functions. You get two equally prominent buttons there: Accept all and Essential only. If you close the banner with the X, we treat that as a refusal.
We use what Google calls Consent Mode v2. That means that, before any consent is given, the settings for ad storage, ad user data, ad personalisation and analytics storage are all set to denied by default. Only once you agree in the banner are they set to granted. We have deliberately switched enhanced conversions off for good. That feature would send contact details to Google in encrypted form.
Your decision itself is stored in your browser, in local storage, under the entry cookie-consent. That is technically necessary so that we do not have to ask you again every time you open a page. The entry stays in your browser until you delete the website data there.
This is how to withdraw your consent: delete the website data for this site in your browser settings. The banner will then appear again on your next visit and you can make a fresh choice. Alternatively, just send a short message to info@physioplustherapie.com and we will sort it out for you.
12. Google Ads and Conversion Tracking
We run ads with Google so that people looking for physiotherapy in Berlin-Charlottenburg find our practice. To see which ad actually leads to someone getting in touch, we use Google Ads conversion tracking with the conversion ID AW-18111570599. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
What is measured is not what you read on our site, but whether you click one of the three ways of contacting us: the phone number, the WhatsApp link or the email address. We count a click like that as one contact.
We should be straight with you about one thing: Google's tracking script loads whenever one of our pages opens, whether or not you have given consent. That transfers your IP address to Google, simply because your browser has to fetch the script.
Without your consent, this is what happens: no advertising cookies are stored on your device and nothing already stored there is read. Google receives only cookieless signals that cannot be traced back to you, from which it works out a statistical estimate of how well the ads perform. We do not link any of it to you personally, and we could not even if we wanted to.
If you do consent, this happens as well: Google can set and read cookies, including a click identifier issued when someone clicks an ad. That makes it possible to link your click on an ad with the fact that you later got in touch. According to Google, this click identifier is stored in your browser for up to 90 days.
Google only gives us aggregated reports, for example the number of times someone got in touch per ad. We cannot tell from them which person clicked a particular ad. We have deliberately switched enhanced conversions off in our account; that feature would also send Google encrypted contact details.
Google also processes data in the USA. You can read more in the section "Data Transfers to the USA". You can withdraw your consent at any time, as described in the section "Consent Banner and Google Consent Mode v2".
13. Google Maps
On our contact page we show a map with our location. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
We do not embed the map automatically. At first you only see a preview with our address and a Load map button. The map is only actually loaded from Google when you click that button, or if you have agreed in the consent banner. Until then, none of your data is sent to Google.
Once the map loads, Google receives your IP address along with details about your browser and operating system, and it can use cookies and similar technologies on your device. If you are signed in to a Google account at the time, Google can link that visit to your account. If you would rather it did not, sign out of Google first, or simply leave the map unloaded.
The map is not a necessary part of this website. Our address is Kaiser-Friedrich-Straße 79, 10585 Berlin. The practice is on the ground floor and is wheelchair accessible. So you can find your way without the map, or just ask us for directions.
14. Website Analytics with Vercel Web Analytics and Vercel Speed Insights
To understand which pages of our website people read and how quickly they load, we use two analytics services from our hosting provider: Vercel Web Analytics and Vercel Speed Insights. The provider is Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA, which acts for us as a processor under Article 28 of the General Data Protection Regulation.
Both services work without cookies. No cookies are set and nothing stored on your device is read. We also do not track you across other websites.
For each page view, Vercel Web Analytics records the time, the page address and the route pattern behind it, the page you visited before, filtered address parameters, a rough location at country, region and city level, operating system, browser, device type and the version of the tracking script. Visitors are not recognised by a cookie but by a hash value calculated from the incoming request. That hash is discarded after 24 hours. Your IP address is not stored.
Vercel Speed Insights measures how quickly the page loads for you, for example how long it takes until the first content appears. It records the page address and the route pattern, the estimated network speed, browser, operating system, device type, the country as a two-letter code, the measurement itself, and the version of the software in use. This data cannot be traced back to a person.
We use these figures only to improve the website, both its content and the technology behind it. They tell us nothing about individual people, and we do not combine them with any other data.
Vercel is based in the USA. There is more on this in the section "Data Transfers to the USA".
15. Applications for Our Advertised Vacancy
We publish our job adverts at /en/jobs. You can apply by email, on WhatsApp or by phone. For a first contact, a short message with your name, your phone number, how many hours you are looking for and when you could start is enough for us. You can send us a CV later.
We process what you send us only in order to run the recruitment process and to decide whether to offer you the job. Inside the practice, only the people involved in that decision have access. We do not pass it on to anyone else.
If you apply on WhatsApp, everything said about that channel in the section "Contacting Us via WhatsApp" applies as well. It is up to you whether you use it. Email and phone reach us just as easily.
How long we keep it: if we turn your application down, we delete your application documents no later than six months after the process ends. We need that time so that we can still provide evidence if anyone brings a claim under the Allgemeines Gleichbehandlungsgesetz (German General Equal Treatment Act). If you expressly agree to us keeping your documents for future vacancies, we store them for twelve months from the date of your consent and delete them after that. You can withdraw this consent at any time. If we do take you on, we transfer the necessary documents into your personnel file.
Please do not send us health information, or details about religion, ethnic background or anything similar, unless we are expressly allowed to ask about it. We do not need any of that to assess your application.
16. Recipients and Processors at a Glance
We only pass your data on where this is necessary for the purposes described above or where a law requires us to. To keep things clear, here is a list of everyone who could ever receive data about you.
Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. What they do: host this website, keep the access logs, and run our website analytics and load time measurement. Their role: processor under Article 28 of the General Data Protection Regulation.
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. What they do: Google Ads with conversion tracking, and Google Maps. Google LLC in the USA may also be involved in delivering these services.
WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. What they do: run the messenger service if you write to us on WhatsApp. WhatsApp Ireland is the controller in its own right for the metadata this creates, and in that respect it is not acting on our behalf.
Beyond that, the following may receive data about you: our tax advisers and our bank in connection with billing, your health insurer or whoever else is paying for your treatment, where this is necessary to bill for it, and public authorities and courts, where we are legally obliged to provide information.
We do not sell your data. We do not pass it on to anyone for advertising purposes either.
17. Data Transfers to the USA
Some of the providers we use are based in the USA or rely on companies in their group that are based there. This concerns our hosting provider Vercel as well as the services from Google and WhatsApp.
The USA is a third country outside the European Union. Data protection there does not match European standards in every respect. In particular, US authorities can access data under certain conditions without you finding out about it or being able to challenge it to the same extent as you could in the European Union.
On 10 July 2023 the European Commission adopted an adequacy decision for the USA on the basis of the EU-US Data Privacy Framework. Companies certified under this framework count as recipients with an adequate level of protection. Vercel Inc. and the Google companies are certified under it. On top of that, we have agreed the European Commission's standard contractual clauses with our processors, so that transfers stay safeguarded even if something changes about the certification.
We want to be clear with you: this adequacy decision is currently being reviewed by the courts. If it falls away, we will look at the services concerned again and update this policy.
If you would rather avoid a transfer to the USA: use the consent banner to refuse the advertising and analytics functions, do not load the map, and contact us by phone or email instead of on WhatsApp. You cannot avoid US providers entirely, because our hosting provider is based there and because Google's script loads as soon as a page opens, as described in the section "Google Ads and Conversion Tracking". Refusing in the banner does stop cookies being set and stops your data being used for advertising.
18. Storage Periods at a Glance
We only keep personal data for as long as the purpose in question requires or the law demands. So you can see it all in one place, here are the actual periods:
Server access logs: deleted automatically by our hosting provider, after no more than 30 days depending on the plan.
Email enquiries and phone notes where no treatment follows: deleted no later than six months after our final reply.
WhatsApp chat histories on the practice device: deleted no later than three months after the conversation has ended.
Entries in the appointment book: destroyed securely once the year in question is complete and the following quarter has ended. Anything that has to be recorded for your treatment is transferred to your treatment notes beforehand.
Patient records: kept for ten years after treatment ends, under Section 630f (3) of the Bürgerliches Gesetzbuch (German Civil Code), unless other rules require us to keep them longer.
Billing and accounting records: kept for the periods set by tax and commercial law, then deleted.
Application documents after a rejection: deleted no later than six months after the process ends, or, if you are in our talent pool, twelve months from the date of your consent.
Your decision in the consent banner: stored in your browser until you delete the website data there.
Google Ads click identifier where you have given consent: stored in your browser for up to 90 days.
Hash value used by Vercel for website analytics: discarded after 24 hours.
19. Your Rights
These are your rights, and you can exercise them with us at any time. There is no set procedure: a phone call or a word at our reception desk is enough. We will answer your request without undue delay and within one month at the latest. It costs you nothing.
Access under Article 15 of the General Data Protection Regulation: you can find out whether we hold any data about you and, if so, what it is, what we use it for, who has received it and how long we keep it. You can ask for a copy of that data.
Rectification under Article 16: if something is wrong or incomplete, we will correct it or fill in the gap.
Erasure under Article 17: you can ask us to erase your data. This does not apply where the law requires us to keep it, in particular your patient record.
Restriction of processing under Article 18: instead of deleting your data, we can simply block it, for example while we check whether it is correct.
Data portability under Article 20: we will give you, or any body you name, the data you provided on the basis of consent or a contract, in a common, machine-readable format.
Objection under Article 21: you can object at any time to processing that we base on a legitimate interest. In our case that means our website analytics and our ad performance reporting. We will then stop processing your data unless we can demonstrate compelling legitimate grounds for continuing. If you object to direct marketing, we always comply, no questions asked.
Withdrawal of consent under Article 7 (3): you can withdraw any consent you have given us at any time, with effect for the future. This applies to the consent banner and to keeping application documents. Withdrawing is as easy as giving consent: a phone call, a word at reception, an informal email. The lawfulness of the processing carried out up to that point is not affected.
Here is how to reach us: Anker Physio und Therapie GmbH, Kaiser-Friedrich-Straße 79, 10585 Berlin, telephone 030 488 148 59, email info@physioplustherapie.com.
To make sure we never hand your data to the wrong person, we may need to check that it really is you before we answer an access request. We hope you understand.
20. Right to Lodge a Complaint with the Supervisory Authority
If you think we are breaking data protection law in the way we handle your data, you can lodge a complaint with a data protection supervisory authority. You have that right whether or not you have come to us first, and it costs you nothing.
The authority responsible for our practice is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information) Alt-Moabit 59-61 10555 Berlin Visitor entrance: Alt-Moabit 60 Telephone: 030 13889-0 Fax: 030 2155050 Email: mailbox@datenschutz-berlin.de Website: www.datenschutz-berlin.de
You can also contact the supervisory authority where you usually live or where you work.
Either way, we would be glad if you came to us first. A lot can be sorted out in a short conversation.
21. Data Security
This website is only ever delivered over an encrypted connection. You can tell by the address beginning with https and by the padlock symbol in your browser. That means nobody can see which of our pages you visit or what you type into the contact form, for as long as the data is still on your device.
These are some of the ways we protect your data at the practice: treatment records are kept locked away, screens and paperwork cannot be seen from the waiting area, only people who need the data for their work are given access, every member of staff signs a written confidentiality obligation and receives training, devices are password protected, and the deletion periods listed in the section "Storage Periods at a Glance" apply to every kind of data.
We owe you an honest word about the residual risk: sending data over the internet can never be made completely secure. There is no such thing as watertight protection against access by third parties. That is why we ask you once again not to send us detailed health information by email or messenger, but to talk it through on the phone or at the practice.
22. Version Date and Changes to This Privacy Policy
This privacy policy is dated 21 August 2026.
We update it whenever something changes on our website, in how we work at the practice, or in the law. If we start offering automatic appointment reminders in future, we will describe that here beforehand and give the name and registered office of the company we engage, before the first message goes out.
You can always find the version currently in force on this page at www.physioplustherapie.berlin/datenschutz. The English version at www.physioplustherapie.berlin/en/privacy is a translation offered for convenience. The German version is the binding one.