SpitalVerse Privacy Policy

1. Controller

The entity responsible for data processing (“Controller”) under the GDPR (Art. 4 DSGVO) and German Telemedia Act (TMG) is:

SpitalVerse – Sole Proprietorship of Nabel Alsulaiman
Sundgauallee 26
79110 Freiburg im Breisgau
Germany

Email: support@spitalverse.com
Phone: +49 163 199 2658
Website: www.spitalverse.com

Responsible according to §§ 5, 6 TMG and Art. 4 DSGVO:
Nabel Alsulaiman


2. Data We Collect

a. Data Provided Voluntarily

This includes information submitted directly by users:

  • Name

  • Email address

  • Phone number

  • Information provided through forms, inquiries, or contact requests

b. Data Collected Automatically

When accessing our website, we automatically collect:

  • IP address

  • Browser type and version

  • Operating system

  • Pages accessed and duration of visit

  • Interaction and usage patterns

  • Cookies & tracking identifiers (see Section 7)

c. Server Logfiles

Our hosting provider automatically stores:

  • Timestamp of access

  • Referrer URL

  • Amount of data transferred

  • Server response/status code

This data is required for system security, stability, and performance monitoring.


3. Legal Basis for Data Processing (Art. 6 GDPR)

We process personal data based on:

  • Art. 6(1)(a) – consent given by the user

  • Art. 6(1)(b) – contract performance or pre-contractual measures

  • Art. 6(1)(c) – compliance with legal obligations

  • Art. 6(1)(f) – legitimate interests such as:

    • website optimization

    • security management

    • analytics and performance monitoring


4. How We Use Your Data

Personal data is used to:

  • respond to inquiries and provide customer support,

  • operate and improve our services and digital health tools,

  • conduct analytics and security assessments,

  • fulfill contractual and legal obligations (e.g., invoicing),

  • prevent misuse, fraud, or unauthorized access,

  • enhance user experience and platform stability.


5. Data Sharing

We do not sell or rent personal data.

Data may be shared with:

  • verified technical service providers (hosting, email delivery, analytics),

  • data processors under Art. 28 GDPR,

  • public authorities when legally required.

All third-party providers operate under GDPR-compliant data processing agreements.


6. Third-Party Tools & Integrations

Depending on usage, our website may include integrations such as:

  • Hosting provider analytics and logfiles

  • Google Analytics or comparable analysis tools

  • Cookie-based tracking and performance tools

  • Embedded content (YouTube, Instagram, TikTok, LinkedIn)

These providers may collect data according to their own Privacy Policies.


7. Cookies & Tracking Technologies

We use cookies to:

  • analyze traffic and performance,

  • understand user behavior,

  • optimize functionality and user experience.

Users may deactivate or delete cookies at any time through their browser settings.
Some features may not function without cookies.


8. Data Retention

We store personal data only as long as necessary for:

  • the purposes described in this policy,

  • the fulfillment of contracts,

  • statutory retention periods (e.g., tax and accounting laws).


9. Data Security

We apply technical and organizational measures to protect personal data, including:

  • SSL/HTTPS encryption,

  • secure and monitored servers,

  • access control protocols,

  • continuous system monitoring.

Nevertheless, no digital system can offer absolute protection against all cyber threats.


10. Third-Party Links

Our website may contain links to external third-party websites.
We are not responsible for the content or privacy practices of those sites.


11. Your Rights Under GDPR (Art. 15–21)

Users have the following rights:

  • Right of access (Art. 15)

  • Right to rectification (Art. 16)

  • Right to erasure (Art. 17)

  • Right to restriction of processing (Art. 18)

  • Right to data portability (Art. 20)

  • Right to object (Art. 21)

To exercise these rights, contact:
📧 support@spitalverse.com


12. Updates to This Policy

We may update this Privacy Policy due to:

  • legal or regulatory changes,

  • new services or functionalities,

  • technological advancements.

The latest version is always available at:
www.spitalverse.com/privacy


13. Contact

SpitalVerse – Sole Proprietorship of Nabel Alsulaiman
Sundgauallee 26
79110 Freiburg im Breisgau
Germany

Email: support@spitalverse.com


This Privacy Policy applies to:

  • Website

  • YouTube

  • Instagram

  • TikTok

  • LinkedIn

  • AI tools and digital applications

  • E-Commerce operations

Fully compliant with GDPR, TMG, and EU privacy regulations.