Privacy policy

The responsible body within the meaning of the data protection laws, in particular the EU General Data Protection Regulation (DSGVO), is:

Anna Frischknecht Naturopathic Practice
Anna Frischknecht
Säntisstrasse 9
8123 Ebmatingen

Switzerland

Phone: +41 79 214 21 11
E-mail: praxis@anna-frischknecht.ch
WebSite: https://www.anna-frischknecht.ch/

2023 version

I, Anna Frischknecht / Anna Frischknecht naturopathy practice, Claridenstrasse 36, 8002 Zurich, hereby confirm that I shall abide by the following rules pursuant to the Data Protection Act and Data Protection Regulation. 

The purpose of this privacy policy is to inform you as the patient about how I handle your personal and sensitive data that are gathered in my practice.

Only data related to the alternative medicine treatment or relevant for information about possible offerings shall be processed. These data are exclusively data that I have gathered with your consent, with which you have provided me or that are publicly available (telephone book, etc.). They can be general data about you (name, address, telephone number, etc.), information about your health/progression of a disease, diagnoses already given and, if necessary, other data, which you have disclosed due to the treatment (patient files).

This data is collected, stored and processed exclusively in your patient dossieror in the dossier required for administration, in particular in the app required for invoicing in accordance with tariff 590. All processing steps carried out on your data, including the persons responsible, can be traced in these two storage locations.

We only pass on your personal data to people or areas of our practice that require them to fulfil contractual or statutory obligations. They are informed about the applicable data protection rules and bound to comply with them. 

Your data or parts thereof shall only be made available to other persons or institutions (insurer, etc.) with your explicit consent. Exceptions are judicial orders or the enforcement of legitimate claims on the part of the practice.

Insofar as your data are physically collected and processed, they shall be stored in a lockable room or cabinet that cannot be accessed by unauthorised third parties. Electronically collected data are stored safely (firewall, password, etc.).

Unless otherwise stipulated by cantonal or other legal provisions, your data that I have collected shall be deleted twenty years after your last consultation in my practice.

Written email communication between my practice and you takes place with a standard email encryption program. Unencrypted email communication shall only occur with your written consent.

As a past or present patient, you can request from me a duplicate of all your data that I have collected in a common electronic format at any time. Data that only exists physically shall be scanned for this purpose and delivered to you in PDF or paper format. The data shall be transferred to you normally free of charge and within a maximum of 30 days.

Anna Frischknecht, Claridenstrasse 36, 8002 Zurich, praxis@anna -frischknecht.ch, +41 79 214 21 11, is responsible for all questions regarding the processing of your personal data and exercise of your rights.

General note

Based on Article 13 of the Swiss Federal Constitution and the data protection provisions of the Swiss Confederation (Data Protection Act, DPA), every person has the right to protection of their privacy as well as protection against misuse of their personal data. The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this data protection declaration.

In cooperation with our hosting providers, we strive to protect the databases as well as possible against unauthorised access, loss, misuse or falsification.

We would like to point out that data transmission on the Internet (e.g. communication by e-mail) can have security gaps. Complete protection of data against access by third parties is not possible.

By using this website, you consent to the collection, processing and use of data as described below. This website can generally be visited without registration. In the process, data such as pages called up or names of the file called up, date and time are stored on the server for statistical purposes without this data being directly related to your person. Personal data, in particular name, address or e-mail address, are collected on a voluntary basis as far as possible. The data will not be passed on to third parties without your consent.

Processing of personal data

Personal data is any information relating to an identified or identifiable person. A data subject is a person about whom personal data is processed. Processing includes any handling of personal data, regardless of the means and procedures used, in particular the storage, disclosure, acquisition, deletion, storage, modification, destruction and use of personal data.

We process personal data in accordance with Swiss data protection law. Furthermore, we process personal data in accordance with the following legal bases in connection with Art. 6 para. 1 DSGVO - insofar as and to the extent that the EU-DSGVO is applicable:

  • Consent (Art. 6 para. 1 p. 1 lit. a. DSGVO) - The data subject has given his/her consent to the processing of personal data relating to him/her for a specific purpose or purposes.
  • Contract performance and pre-contractual requests (Art. 6 para. 1 p. 1 lit. b. DSGVO) - Processing is necessary for the performance of a contract to which the data subject is party or for the performance of pre-contractual measures taken at the data subject's request.
  • Legal obligation (Art. 6 para. 1 p. 1 lit. c. DSGVO) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Protection of vital interests (Art. 6 para. 1 p. 1 lit. d. DSGVO) - Processing is necessary to protect the vital interests of the data subject or another natural person.
  • Legitimate interests (Art. 6 para. 1 p. 1 lit. f. DSGVO) - Processing is necessary to protect the legitimate interests of the controller or a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.
  • Application procedure as a pre-contractual or contractual relationship (Art. 9(2)(b ) GDPR) - Insofar as special categories of personal data within the meaning of Art. 9(1) GDPR (e.g. health data, such as severely disabled status or ethnic origin) are requested from applicants in the context of the application procedure so that the controller or the data subject can exercise the rights accruing to him or her under labour law and social security and social protection law and fulfil his or her obligations in this respect, they are processed in accordance with Art. 9(2)(b). If the data protection officer or the data subject asks for data from job applicants (e.g. health data such as severely disabled person or ethnic origin) so that the data protection officer or the data subject can exercise his or her rights under labour law and social security law and fulfil his or her obligations in this respect, the data is processed in accordance with Art. 9 (2) lit. b. DSGVO, in the case of the protection of vital interests of the applicants or other persons pursuant to Art. 9 para. 2 lit. c. DSGVO or for the purposes of preventive health care or occupational medicine, for the assessment of the employee's fitness for work, for medical diagnostics, care or treatment in the health or social sector or for the management of systems and services in the health or social sector pursuant to Art. 9 para. 2 lit. h. DSGVO. In the case of a communication of special categories of data based on voluntary consent, their processing is based on Art. 9 para. 2 lit. a. DSGVO.

We process personal data for the period of time required for the respective purpose or purposes. In the case of longer-term retention obligations due to legal and other obligations to which we are subject, we restrict processing accordingly.

Relevant legal bases

In accordance with Art. 13 DSGVO, we inform you about the legal basis of our data processing. If the legal basis is not stated in the data protection declaration, the following applies: The legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 DSGVO, the legal basis for processing to fulfil our services and carry out contractual measures and respond to enquiries is Art. 6(1)(b) DSGVO, the legal basis for processing to fulfil our legal obligations is Art. 6(1)(c) DSGVO, and the legal basis for processing to protect our legitimate interests is Art. 6(1)(f) DSGVO. In the event that vital interests of the data subject or another natural person make processing of personal data necessary, Art. 6 (1) (d) DSGVO serves as the legal basis.

Safety measures

We take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk, in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing, as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons.

The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, entry, disclosure, safeguarding of availability and its separation. We also have procedures in place to ensure the exercise of data subjects' rights, the deletion of data and responses to data compromise. Furthermore, we already take the protection of personal data into account in the development or selection of hardware, software and procedures in accordance with the principle of data protection, through technology design and through data protection-friendly default settings.

Transmission of personal data

In the course of our processing of personal data, the data may be transferred to or disclosed to other bodies, companies, legally independent organisational units or persons. The recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude appropriate contracts or agreements that serve to protect your data with the recipients of your data.

Data processing in third countries

If we process data in a third country (i.e., outside the European Union (EU), the European Economic Area (EEA)) or the processing takes place in the context of the use of third-party services or the disclosure or transfer of data to other persons, bodies or companies, this is only done in accordance with the legal requirements.

Subject to express consent or contractually or legally required transfer, we process the data only in third countries with a recognised level of data protection, contractual obligation through so-called standard protection clauses of the EU Commission, in the presence of certifications or binding internal data protection regulations (Art. 44 to 49 DSGVO, information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).

Privacy policy for cookies

This website uses cookies. Cookies are text files that contain data from visited websites or domains and are stored by a browser on the user's computer. A cookie is primarily used to store information about a user during or after their visit within an online offering. Stored information may include, for example, language settings on a website, login status, a shopping cart or where a video was watched. The term cookies also includes other technologies that perform the same functions as cookies (e.g. when user details are stored using pseudonymous online identifiers, also known as "user IDs").

The following cookie types and functions are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offer and closed his browser.
  • Permanent cookies: Permanent cookies remain stored even after the browser is closed. For example, the login status can be saved or preferred content can be displayed directly when the user visits a website again. Likewise, the interests of users, which are used for range measurement or marketing purposes, can be stored in such a cookie.
  • First-party cookies: First-party cookies are set by us.
  • Third-party cookies (also: third-party cookies): Third-party cookies are mainly used by advertisers (so-called third parties) to process user information.
  • Necessary (also: essential or absolutely necessary) cookies: Cookies may be absolutely necessary for the operation of a website (e.g. to save logins or other user entries or for security reasons).
  • Statistics, marketing and personalisation cookies: Furthermore, cookies are usually also used in the context of range measurement and when a user's interests or behaviour (e.g. viewing certain content, using functions, etc.) on individual websites are stored in a user profile. Such profiles are used, for example, to show users content that matches their potential interests. This process is also referred to as "tracking", i.e. tracking the potential interests of users. Insofar as we use cookies or "tracking" technologies, we will inform you separately in our data protection declaration or in the context of obtaining consent.

Notes on legal bases: The legal basis on which we process your personal data using cookies depends on whether we ask you for consent. If this is the case and you consent to the use of cookies, the legal basis for the processing of your data is the consent given. Otherwise, the data processed using cookies is processed on the basis of our legitimate interests (e.g. in the business operation of our online offer and its improvement) or, if the use of cookies is necessary to fulfil our contractual obligations.

Storage period: If we do not provide you with explicit information on the storage period of permanent cookies (e.g. in the context of a so-called cookie opt-in), please assume that the storage period can be up to two years.

General information on revocation and objection (opt-out): Depending on whether the processing is based on consent or legal permission, you have the option at any time to revoke any consent you have given or to object to the processing of your data by cookie technologies (collectively referred to as "opt-out"). You can initially declare your objection by means of your browser settings, e.g. by deactivating the use of cookies (whereby this may also restrict the functionality of our online offer). An objection to the use of cookies for online marketing purposes can also be declared by means of a variety of services, especially in the case of tracking, via the https://optout.aboutads.info and https://www.youronlinechoices.com/ websites. In addition, you can obtain further instructions on how to object within the scope of the information on the service providers and cookies used.

Processing of cookie data on the basis of consent: We use a cookie consent management procedure in which the consent of users to the use of cookies, or to the processing and providers mentioned in the cookie consent management procedure, can be obtained and managed and revoked by users. The declaration of consent is stored in order not to have to repeat the request and to be able to prove the consent in accordance with the legal obligation. The storage can take place on the server side and/or in a cookie (so-called opt-in cookie or with the help of comparable technologies) in order to be able to assign the consent to a user or their device. Subject to individual information on the providers of cookie management services, the following information applies: The duration of the storage of consent can be up to two years. A pseudonymous user identifier is created and stored with the time of consent, information on the scope of consent (e.g. which categories of cookies and/or service providers) and the browser, system and end device used.

  • Types of data processed: Usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Legal basis: Consent (Art. 6 para. 1 p. 1 lit. a. DSGVO), Legitimate Interests (Art. 6 para. 1 p. 1 lit. f. DSGVO).

Privacy policy for SSL/TLS encryption

This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content, such as enquiries that you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Third party services

This website may use Google Maps for embedding maps, Google Invisible reCAPTCHA for protection against bots and spam, and YouTube for embedding videos.

These services of the American Google LLC use cookies, among other things, and as a result, data is transferred to Google in the USA, although we assume that no personal tracking takes place in this context solely through the use of our website.

Google has committed to ensuring adequate data protection in accordance with the US-European and US-Swiss Privacy Shields.

Further information can be found in Google's privacy policy.

Privacy policy for Google Analytics

This website uses Google Analytics, a web analytics service provided by Google Ireland Limited. If the data controller on this website is located outside the European Economic Area or Switzerland, the Google Analytics data processing is carried out by Google LLC. Google LLC and Google Ireland Limited are hereinafter referred to as "Google".

The statistics obtained enable us to improve our offer and make it more interesting for you as a user. This website also uses Google Analytics for a cross-device analysis of visitor flows, which is carried out via a user ID. If you have a Google user account, you can deactivate the cross-device analysis of your usage in the settings there under "My data", "Personal data".

The legal basis for the use of Google Analytics is Art. 6 para. 1 p. 1 lit. f DS-GVO. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. We would like to point out that on this website Google Analytics has been extended by the code "_anonymizeIp();" in order to ensure anonymised collection of IP addresses. This means that IP addresses are processed in abbreviated form, thus excluding the possibility of personal references. If the data collected about you is related to a person, this is immediately excluded and the personal data is immediately deleted.

Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator.

Google Analytics uses cookies. The information generated by the cookie about your use of this website is generally transmitted to a Google server in the USA and stored there. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. In addition, you can prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available under the following link: Deactivate Google Analytics.

You can also prevent the use of Google Analytics by clicking on this link: Deactivate Google Analytics. This will save a so-called opt-out cookie on your data carrier, which prevents the processing of personal data by Google Analytics. Please note that if you delete all cookies on your terminal device, these opt-out cookies will also be deleted, i.e. you will have to set the opt-out cookies again if you wish to continue to prevent this form of data collection. The opt-out cookies are set per browser and computer/end device and must therefore be activated separately for each browser, computer or other end device.

Privacy policy for the use of Google Web Fonts

This website uses so-called web fonts provided by Google for the uniform display of fonts. When you call up a page, your browser loads the required web fonts into its browser cache in order to display texts and fonts correctly. If your browser does not support web fonts, a standard font is used by your computer.

Further information on Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/

Changes

We may amend this privacy policy at any time without prior notice. The current version published on our website will apply. Insofar as the data protection declaration is part of an agreement with you, we will inform you of the change by e-mail or other suitable means in the event of an update.

Questions to the Data Protection Officer

If you have any questions about data protection, please write to us by e-mail or contact the person in our organisation responsible for data protection listed at the beginning of this privacy policy directly.