Enovis Logo

Privacy Policy

Privacy Policy

Ormed GmbH | Bötzinger Str. 90 | 79111 Freiburg
Telephone: +49 761 456601 | E-Mail: kundenservice@enovis.com | Web: www.enovis-medtech.de

Privacy at a Glance

This Privacy Policy applies to all our online presences as well as to the processing of personal data of our patients, employees and applicants.

What happens to your data?

Personal data is any data by which you can be personally identified. We collect and process such data only to the extent permitted by law or with your consent. Some data is collected automatically when you visit our websites (technical data such as IP address, browser, time). Other data is provided directly by you, for example via contact forms.

Note on internet security: Please note that data transmission over the internet (e.g. when communicating by e-mail) may have security vulnerabilities. Complete protection of data from access by third parties is not possible.

What rights do you have?

You have the right at any time to receive free information about the origin, recipient and purpose of your stored personal data, as well as the right to rectification, restriction or deletion of this data. You also have the right to lodge a complaint with the competent supervisory authority. For detailed information on your rights, see Section 15.

Scope: Main Website

Address / Context https://www.enovis-medtech.de

Target Group: All visitors, patients, specialist audience


Scope: Customer Portal

Address / Context: https://enovis-kundenportal.de/de

Target Group: B2B specialist partners (orthopaedic supply stores, clinics, medical practices)


Scope: Patient care

Address / Context: Care process

Target Group: Treated patients


Scope: Employees

Address / Context: Employment relationship

Target Group: Current employees


Scope: Applicants

Address / Context: Application process

Target Group: Applicants

1. Controller and Data Protection Officer

1.1 Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) for all processing activities described in this declaration is:

Ormed GmbH

Bötzinger Straße 90

79111 Freiburg

Telephone: +49 (0)761 456601

E-Mail: kundenservice@enovis.com

Approved assistive device supplier pursuant to § 126 SGB V (German Social Code, Book V).

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

1.2 Data Protection Officer

As we regularly process special categories of personal data (in particular health data pursuant to Art. 9 GDPR), we are obliged pursuant to Art. 37 GDPR in conjunction with § 38 BDSG to appoint a Data Protection Officer and have designated Martin Möhrle as internal Data Protection Officer.

1.3 Central Contact Information

For all data protection enquiries, complaints and to withdraw consent, please contact our Data Protection Officer:

Martin Möhrle 

Data Protection Officer of Ormed GmbH 

Bötzinger Straße 90 

79111 Freiburg

Telephone: +49 (0)761 4566131

E-Mail: datenschutzbeauftragter@enovis.com

Response time: All enquiries will be processed without undue delay, at the latest within 30 days.

Note: These contact details cover all processing activities described in this Privacy Policy. See also Sections 16 and 17 for further information on your rights and the complaints procedure.

1.4 Third-Country Transfers – Standard Safeguards

For certain processing operations, data is transferred to the USA and other third countries. These transfers are safeguarded by the following mechanisms:

EU-US Data Privacy Framework (DPF): Certification of the data recipient under the DPF

EU Standard Contractual Clauses (SCC): Contractual clauses pursuant to Art. 46(2)(c) GDPR

Data Processing Agreements (DPA): Agreements pursuant to Art. 28 GDPR for processors

Works Agreements: Agreements pursuant to Art. 88 GDPR in conjunction with § 26 BDSG

Residual risk: Despite these safeguards, a theoretical residual risk of government access to data in the USA (CLOUD Act) exists. This risk has been assessed and consciously accepted.

Note on the combination of DPF and SCC: Where providers are both DPF-certified and have concluded EU Standard Contractual Clauses (SCC), the SCC serve as a fallback in the event that DPF certification lapses or is suspended (cf. Privacy Shield, invalid since Schrems II, CJEU C-311/18). Maintaining both mechanisms in parallel reflects the principle of accountability and legal certainty (Art. 5(2) GDPR). For employee data (Workday), cumulative safeguarding through DPF and SCC is additionally recommended under data protection law, as the DPF does not explicitly address employee data protection pursuant to Art. 88 GDPR in conjunction with § 26 BDSG.

Specific applications:

See Sections

4.3 (Vercel – web hosting main website, USA), 

4.4 (Cloudflare – WAF / DDoS protection customer portal, USA), 

5.2 (Google reCAPTCHA – bot protection forms, USA), 

7.5 (Salesforce – CRM / sales / marketing, USA), 

8 (Oracle EBS – B2B order processing, USA), 

9.5 (Google Analytics 4 – web analytics / campaign measurement, USA),

13.3.1 (Workday – HR system for employees, USA), 

13.3.5 (RingCentral – telephony, USA / NICE call centre software, Israel), 

14.2 (Workday – applicant management, USA).

Note: Patient and health data are NOT transferred to third countries (see Sections 3 and 6.5).

2. Group Affiliation (Enovis)

We are part of the Enovis Group (Enovis Corporation, 2711 Centerville Road, Wilmington, Delaware 19808, USA). In addition to our own products, we also distribute products that have been approved across the Enovis Group.

Intra-group data transfers occur:

  • in the B2B context via Oracle EBS (order processing in Section 8)
  • in the employment context via Workday (personnel management for employees in Section 13.3.1, for applicants in Section 14.2)

Third-country transfers to the USA are based on the safeguarding mechanisms described in Section 1.4.

Patient data and health data are not transferred to intra-group entities or to third countries at any time. They remain exclusively in the systems hosted in Germany (Section 6.5).

3. Special Features of Data Processing in the Healthcare Sector

As an approved assistive device supplier for CPM (Continuous Passive Motion) devices pursuant to § 126 SGB V, we process health data within the meaning of Art. 4(15) in conjunction with Art. 9 GDPR in the course of our care activities. Such data is subject to particularly strict legal protection.

Legal bases for health data:

  • Art. 9(2)(h) GDPR in conjunction with § 22(1)(1)(b) BDSG (healthcare and billing)
  • Art. 9(2)(i) GDPR (quality and safety standards in healthcare and medical devices)
  • Art. 9(2)(a) GDPR (explicit consent, in particular for self-paying patients)
  • Art. 6(1)(c) GDPR (legal obligations, in particular § 302 SGB V, MDR, MPDG)
  • §§ 67 et seq. SGB X (social data protection, where social data within the meaning of SGB X is processed)

Health data is processed and stored exclusively in Germany. No transfer to third countries takes place for this category of data.

4. Provision of the Websites and Server Log Files

Applicable to: www.enovis-medtech.de and https://enovis-kundenportal.de/de

4.1 Server Log Files

Each time our websites are accessed, the responsible hosting or infrastructure provider automatically collects information in so-called server log files containing information that your browser transmits automatically:

Data processed:

  • IP address of the accessing device
  • Date and time of access
  • URL accessed and data volume transmitted
  • Browser type and version, operating system
  • Referrer URL (source page)

These data are not merged with other data sources.

Purpose: Technical provision of the website, error analysis, IT security.

Retention period: The retention period depends on the system used. Unless a different period is specified for the systems listed by us, a standard retention period of 7 days applies, after which automatic deletion occurs.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technically sound presentation and optimisation of the website).

4.2 SSL / TLS Encryption

Our websites use SSL or TLS encryption for security reasons and to protect the transmission of confidential content. You can recognise an encrypted connection by the fact that the browser address bar changes from "http://" to "https://" and by the padlock symbol in the browser bar.

Purpose: Protection of data transmission against unauthorised access.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security).

4.3 Web Hosting – Main Website www.enovis-medtech.de

Our main website is operated on servers of an external hosting service provider. Each time the website is accessed, technical connection data is processed on the provider's servers; this is technically necessary for the operation of the website.

Provider: Vercel Inc. Address: 440 N Barranca Ave #4133, Covina, CA 91723, USA

Purpose: Technical operation and provision of the website www.enovis-medtech.de; storage of website files and static assets.

Data processed: IP address, connection metadata (time, duration, data volume), server logs (see also Section 4.1).

Hosting: Global CDN – primarily USA, EU nodes available

Retention period: In accordance with Vercel's retention policies; maximum 30 days; no further personal storage by the hosting provider beyond this period.

Safeguards: DPF certification (EU-US Data Privacy Framework); SCC (EU Standard Contractual Clauses, Art. 46 GDPR); DPA pursuant to Art. 28 GDPR.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technically sound provision of the website).

4.4 Protection against Automated Access – Cloudflare

Applicable to: https://enovis-kundenportal.de/de

All incoming traffic is processed by Cloudflare to protect against bot attacks and abusive access.

Provider: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA.

Purpose:

  • Web Application Firewall (WAF)
  • Bot detection and defence
  • DDoS protection
  • Protection against automated attacks

Data processed:

  • IP address
  • HTTP headers
  • Request metadata
  • Bot detection signals

Technical safeguards:

  • Cloudflare processes data in real time for threat detection
  • Legitimate requests are passed through
  • Suspicious requests are blocked or subjected to a CAPTCHA check

Retention period: 30 days (log data for analysis purposes).

Safeguards: DPF certification (EU-US Data Privacy Framework); SCC (EU Standard Contractual Clauses, Art. 46 GDPR); DPA pursuant to Art. 28 GDPR.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security and protection against cyberattacks); where Cloudflare sets technically necessary cookies: § 25(2) No. 2 TDDDG.

Further information: https://www.cloudflare.com/privacypolicy/

5. Contact Form and General Enquiries

Applicable to: www.enovis-medtech.de and https://enovis-kundenportal.de/de

5.1 Contact Form and E-Mail Contact

If you contact us via contact forms, by e-mail or telephone, we process the data you submit exclusively to handle your enquiry. For service requests via the customer portal (ticketing system), Section 7 additionally applies.

Data processed:

  • Name, e-mail address, telephone number where applicable
  • Content of your message and any attached documents
  • Where health-related: explicit consent pursuant to Art. 9(2)(a) GDPR

Purpose: Processing and responding to your enquiry.

Retention period: Until your enquiry has been fully processed, generally no longer than 6 months; statutory retention obligations (in particular § 257 HGB: 6 years for business correspondence) remain unaffected and may necessitate longer retention.

Legal basis: Art. 6(1)(b) and (f) GDPR; for health data additionally Art. 9(2)(a) GDPR.

We do not pass on this data without your consent.

5.2 Google reCAPTCHA

Applicable to: www.enovis-medtech.de

To protect our forms against abusive automated access, we use Google reCAPTCHA (invisible).

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Purpose: To distinguish human input from automated access (bot protection).

Data processed: Your IP address (this is truncated within the EU/EEA and before transmission to the USA, IP masking active) and, where applicable, further signals required by Google. The IP address is not merged with other Google data.

Safeguards: DPF certification; DPA pursuant to Art. 28 GDPR. See Section 1.4.

Legal basis: § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR (consent).

Further information: https://policies.google.com/privacy

5.3 Chat Widget with Automated FAQ Responses and Direct Forwarding to Staff

Applicable to: www.enovis-medtech.de

On our website we use the chat and contact widget Lime Connect by the provider Userlike GmbH. It enables visitors to quickly obtain answers to frequently asked questions, submit contact requests, arrange appointments or enter into a live chat directly with one of our members of staff. Qualified answers are provided exclusively by our employees.

Provider: Lime Connect (Userlike) GmbH, Kölnturm, Im Mediapark 8, 50670 Cologne; Telephone: 0221-77268620; E-Mail: support@lime-connect.com.

Scope of functions:

  • General FAQ / product information
  • Forwarding contact requests to staff
  • Appointment scheduling
  • Live chat with real employees
  • Conversation logging

Data processed:

  • Contact data (where voluntarily provided): name, e-mail address, telephone number
  • Chat content: text entries and conversation histories
  • Connection data: IP address, time and duration of session, browser type, source page
  • Session data: technical identification features of the chat session

Note on health data: The chat widget is not intended for entering health data or patient-related information. We expressly ask users not to enter any health data, diagnoses or prescription information via the chat. Should such data nonetheless be entered voluntarily, it will be used exclusively for processing the specific enquiry and not processed further. For questions concerning patient care, please contact us directly (see Section 1.3).

Consent: The chat widget is loaded automatically when our website is accessed and requests its own cookie consent before active use. Without confirmation of this consent, no chat content is processed. The chat widget is technically loaded prior to the confirmation of the general cookie banner (Usercentrics); only technically necessary connection data is transmitted at this stage. Processing of content only takes place after your explicit consent.

Withdrawal: The consent given can be withdrawn at any time by closing the chat window or by contacting our Data Protection Officer (see Section 1.3).

Hosting: Germany (provider based in Cologne).

Safeguards: DPA pursuant to Art. 28 GDPR in place; no data sharing with third-party systems; no third-country transfer.

Retention periods:

  • Chat histories and conversation content: 14 days, then automatic deletion
  • Connection data (technical): 7 days

Legal bases:

  • Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG – consent for active chat use and cookie setting
  • Art. 6(1)(f) GDPR – legitimate interest in the technical provision of the chat widget (pre-loading)
  • Art. 6(1)(b) GDPR – where a user actively submits a specific contact or service request (pre-contractual measures at the request of the data subject)

6. Data Processing in the Context of Patient Care (CPM Devices)

Applicable to: all treated patients – regardless of cost bearer

Information for patients: This section fully describes how we process your data in the context of the provision of a CPM device – from the order placement by your medical practice or clinic through to the collection of the device and billing. Without providing your data, your individual care may not be possible.

6.1 Origin of Patient Data

We receive patient data through various channels – from commissioning entities as well as, in certain cases, directly from patients themselves.

Transmission by prescribers and orthopaedic supply stores (medical supply retailers): As a rule, we receive the data required for care from the entity initiating the care – i.e. the prescribing medical practice, clinic or cooperating orthopaedic supply store. These entities act in coordination with the patients to enable the medically prescribed assistive device supply.

Categories of transmitting entities:

  • Prescribing medical practices and specialists (in particular orthopaedics, surgery, trauma surgery)
  • Clinics and hospitals (inpatient and post-inpatient care)
  • Orthopaedic supply stores (as cooperating service providers)
  • Health insurance funds and other cost bearers (in individual cases, for repeat prescriptions or cost approval applications)

Transmission channels – receipt of prescription data:

The transmission of prescription and patient data by prescribers and orthopaedic supply stores takes place via various technical channels. We expressly recommend the use of secure, encrypted transmission channels and provide a dedicated platform for this purpose:

Secure web form (recommended method): On our website we provide an encrypted web form through which prescriptions and patient data can be transmitted to us securely and end-to-end encrypted. This method meets current requirements for secure data transmission in the healthcare sector.

Other transmission channels: Where prescribers or orthopaedic supply stores transmit data via other channels (e.g. by post or via other channels within their area of responsibility), the data protection responsibility for the chosen transmission channel lies with the transmitting entity. We have no influence over the choice of transmission channel by third parties and process incoming data exclusively for the purpose of assistive device supply.

Post / personal handover: In individual cases, documents are also transmitted by post or in person at the time of device handover.

Direct contact by patients

In certain cases, patients contact us directly and transmit their data themselves. This may occur for various reasons:

Exercise of free choice of provider: Patients have the right to commission the assistive device supplier of their choice. They may therefore contact us independently and submit their prescription and personal data directly.

Self-paying patients (privately or publicly insured): Patients who bear all or part of the cost of care themselves – regardless of whether they are privately or publicly insured – frequently contact us directly to initiate and coordinate the care.

In these cases, the data you actively transmit will be used exclusively for carrying out the assistive device supply and – where applicable – for billing with your cost bearer.

Legal bases for direct contact:

  • Art. 6(1)(b) GDPR (contract performance / pre-contractual measures at your request)
  • Art. 9(2)(a) GDPR (explicit consent to the processing of your health data)
  • Art. 9(2)(h) GDPR (healthcare)

6.2 Patient Data Processed

Master and contact data: First and last name, date of birth, home address, delivery address (where different), telephone number

Insurance and cost bearer data (for GKV patients): Health insurance fund, insurance number, insurance status, IK number of the cost bearer

Prescription and diagnosis data: Diagnosis (ICD code), medical prescription (prescription form), prescribed assistive device (aid number), name and contact details of the prescribing practice / clinic, BSNR and LANR of the prescriber, discharge documents from clinics

Care data: Planned care period (rental duration), device data (serial number, configuration), handover and return dates

Billing data: Approval numbers, cost commitments, delivery notes, prescription copies, invoice data

6.3 Care Process and Data Flow

Step 1 – Order receipt and care planning 

We receive the prescription data from the medical practice, clinic or orthopaedic supply store and plan the assistive device supply on this basis. In individual cases, repeat prescriptions or cost commitments may also be received directly from the health insurance fund.

Step 2 – Cost clarification 

For publicly insured patients (GKV): 

Approval for cost coverage is obtained from the responsible health insurance fund or cost bearer – depending on the fund, via a communication platform specified by the cost bearer (electronic approval portals) or through the direct individual case approval process (in particular for smaller health insurance funds). Prescription and insurance data is transmitted to the cost bearer in this context. Care is only initiated after receipt of approval.

Should immediate care be medically urgent and the health insurance fund's approval still outstanding, we may begin care provisionally under the status "self-paying patient." After receipt of the GKV approval, a reimbursement claim is submitted to the health insurance fund. This requires your explicit written consent.

Legal basis: § 302 SGB V in conjunction with Art. 9(2)(h) GDPR, §§ 67 et seq. SGB X.

For self-paying patients (private patients and other self-paying patients): 

The patient is presented with a rental agreement with cost coverage agreement for signature. Care is only initiated after verbal confirmation of cost coverage. By signing the rental agreement, generally at the time of delivery, the patient formally confirms the verbal consent previously given to the processing of their personal data in accordance with this Privacy Policy, as well as their explicit consent to the processing of their health data.

Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 9(2)(a) GDPR (explicit consent for health data).

Step 3 – Telephone care coordination 

After approval by the health insurance fund or agreement on cost coverage by the self-paying patient, care is coordinated by telephone with the patient (delivery date, handover arrangements, instruction). Signature of the rental agreement (for self-paying patients) usually takes place at delivery.

Step 4 – Provision for patient supervisors 

Data required for delivery and patient instruction is made available for retrieval by patient supervisors via a secure portal (see Section 6.4).

Step 5 – Care, instruction and return 

Patient supervisors deliver the CPM device, instruct the patient in its use and collect the device after the expiry of the prescription period.

Step 6 – Billing 

Billing with the statutory health insurance funds is carried out via the qualified data centre RZH (see Section 6.5). For self-paying patients, invoicing is carried out directly.

6.4 Patient Supervisors – Data Sharing and Role Clarification

Patient supervisors are independent service providers who are pre-qualified pursuant to § 126 SGB V. They carry out the direct patient care on site (delivery, device instruction, accompaniment during the care period, collection).

The patient data required for care (name, delivery address, telephone number, device and care data) is made available to patient supervisors via a secure portal – exclusively the information strictly necessary for the respective care provision.

As patient supervisors exercise independent decision-making powers as independent, pre-qualified service providers, they are to be classified under data protection law as independent controllers within the meaning of Art. 4(7) GDPR.

Legal basis: Art. 9(2)(h) GDPR in conjunction with § 22(1)(1)(b) BDSG; Art. 6(1)(b) GDPR.

Secure data exchange with patient supervisors

For the provision of care data to patient supervisors and for bidirectional communication during the care process, we use a secure communication platform of a German provider. Transmission is end-to-end encrypted: the content is technically not accessible to the platform operator. This ensures that:

  • only authorised patient supervisors have access to the care data intended for them (identity verification)
  • bidirectional communication is protected to the same standard

Patient supervisors are provided exclusively with the data strictly necessary for the respective care provision (principle of data minimisation, Art. 5(1)(c) GDPR).

Infrastructure provider: FTAPI Software GmbH, Feringastrasse 9, 85774 Unterföhring (Munich); hosting in Germany; no third-country transfer. An agreement for commissioned processing pursuant to Art. 28 GDPR exists with the provider, governing the processing of the infrastructure and any metadata. Due to end-to-end encryption, the provider has no access to the content of the transmitted care data.

Legal basis: Art. 9(2)(h) GDPR in conjunction with § 22(1)(1)(b) BDSG; Art. 6(1)(b) GDPR.

6.5 Systems and Service Providers Used in Patient Care

All patient data is processed exclusively in the following systems hosted in Germany:

Kumavision AG – Industry software (Microsoft Dynamics NAV / Navision)

  • Purpose: Care planning, prescription management, billing GKV and self-paying patients
  • Hosting: Microsoft Azure Germany
  • Provider: Kumavision AG, Oberfischbach 3, 88677 Markdorf
  • DPA pursuant to Art. 28 GDPR

M Assist GmbH – Consulting and support

  • Purpose: Support and customisation of ERP processes
  • Provider: M Assist GmbH, Camp-Spich-Str. 5, 53842 Troisdorf
  • DPA pursuant to Art. 28 GDPR

H-SAS GmbH – Digital scanning solution for care documents

  • Purpose: Digital capture of prescriptions, cost commitments and billing documents
  • Hosting: Germany
  • Provider: H-SAS GmbH, Camp-Spich-Str. 5, 53842 Troisdorf
  • DPA pursuant to Art. 28 GDPR

FTAPI Software GmbH – Secure data transmission (inbound and outbound)

  • Purpose (inbound): End-to-end encrypted receipt of prescriptions and patient data from prescribers and orthopaedic supply stores via the secure web form provided on our website
  • Purpose (outbound): End-to-end encrypted provision of care data for patient supervisors via a secure communication platform; bidirectional communication
  • Hosting: Germany
  • Provider: FTAPI Software GmbH, Feringastrasse 9, 85774 Unterföhring (Munich)
  • DPA pursuant to Art. 28 GDPR for infrastructure and metadata (in place)
  • No third-country transfer

RZH – Data Centre for Healthcare Professions

  • Purpose: Qualified billing with statutory health insurance funds pursuant to § 302 SGB V
  • Hosting: Germany
  • Provider: RZH Rechenzentrum für Heilberufe GmbH, Am Schornacker 32, 46485 Wesel
  • DPA pursuant to Art. 28 GDPR
  • No third-country transfer

In the context of billing via RZH, patient data (insurance data, prescription data, billing data) is transmitted to RZH, which passes it on to the respective health insurance funds on our behalf and in accordance with their instructions.

Legal basis: § 302 SGB V in conjunction with Art. 9(2)(h) GDPR.

No third-country transfer for patient data. All patient-related data remains in Germany.

6.6 Data Sharing in the Care Process – Overview

Recipient: Statutory health insurance funds (direct)

Purpose: Approval in individual case procedure

Legal Basis: § 302 SGB V, Art. 9(2)(h) GDPR, §§ 67 et seq. SGB X


Recipient: Communication platforms of the funds

Purpose: Electronic approval procedure

Legal Basis: § 302 SGB V, Art. 9(2)(h) GDPR


Recipient: RZH (data centre)

Purpose: Collective billing with health insurance funds

Legal Basis: § 302 SGB V, Art. 9(2)(h) GDPR; DPA Art. 28 GDPR


Recipient: Patient supervisors

Purpose: Delivery, instruction, collection

Legal Basis: Art. 9(2)(h) GDPR, Art. 6(1)(b) GDPR


Recipient: Prescribing doctors / clinics

Purpose: Follow-up queries on prescription, extensions

Legal Basis: Art. 9(2)(h) GDPR, Art. 6(1)(b) GDPR


Recipient: FTAPI Software GmbH

Purpose: Provision of secure transmission infrastructure (inbound: prescribers / orthopaedic supply stores; outbound: patient supervisors); no knowledge of content due to end-to-end encryption

Legal Basis: DPA Art. 28 GDPR (for infrastructure / metadata)


Recipient: Lawyers / public authorities

Purpose: In individual cases where legally necessary

Legal Basis: Art. 6(1)(c) GDPR


Recipient: Kumavision AG / M Assist GmbH

Purpose: System hosting and operation

Legal Basis: DPA Art. 28 GDPR


Recipient: H-SAS GmbH

Purpose: Digital document capture

Legal Basis: DPA Art. 28 GDPR

6.7 Legal Bases Patient Care – Summary

Processing Operation: Care planning based on prescription

Legal Basis: Art. 9(2)(h) and (i) GDPR in conjunction with § 22(1)(1)(b) BDSG


Processing Operation: Cost clarification with GKV

Legal Basis: Art. 9(2)(h) GDPR; § 302 SGB V; §§ 67 et seq. SGB X


Processing Operation: Rental agreement with self-paying patients

Legal Basis: Art. 6(1)(b) GDPR; Art. 9(2)(a) GDPR


Processing Operation: Telephone care coordination

Legal Basis: Art. 6(1)(b) GDPR


Processing Operation: Provision for patient supervisors

Legal Basis: Art. 9(2)(h) GDPR; Art. 6(1)(b) GDPR


Processing Operation: Direct transmission / direct contact by patients

Legal Basis: Art. 6(1)(b) GDPR; Art. 9(2)(a) and (h) GDPR


Processing Operation: Billing via RZH

Legal Basis: Art. 6(1)(c) GDPR; § 302 SGB V


Processing Operation: MDR documentation / vigilance

Legal Basis: Art. 6(1)(c) GDPR (MDR, MPDG)

6.8 Retention Periods – Patient Care

Type of data: Tax and commercial law documents

Retention period: 10 years

Legal Basis: § 147 AO, § 257 HGB


Type of data: Medical device documentation

Retention period: at least 10 years after placing on the market

Legal Basis: MDR (EU 2017/745), MPDG


Type of data: GKV billing documents

Retention period: in accordance with health insurance fund requirements

Legal Basis: § 302 SGB V


Type of data: Social data

Retention period: in accordance with § 84 SGB X

Legal Basis: § 84 SGB X


Type of data: General care correspondence

Retention period: 6 years

Legal Basis: § 257 HGB

6.9 Social Data pursuant to SGB X

Where we process data in the context of fund-based care that originates from or is transmitted to a statutory cost bearer (health insurance fund), this constitutes social data within the meaning of § 67(2) SGB X. This is subject to the special social data protection provisions of §§ 67 et seq. SGB X. We process this data exclusively within the scope of the legally permissible purposes of assistive device supply and billing.

6.10 Online Status Query – Prescription and Approval Status

Applicable to: www.enovis-medtech.de

On our website, patients can retrieve the current processing status of their CPM care online – in particular the status of the approval procedure with the statutory health insurance fund.

How it works: By entering the 10-digit insurance number, the current prescription and approval status can be viewed.

Data processed:

  • Insurance number (10 digits)
  • Query time (server log)
  • IP address (technical, pursuant to Section 4.1)
  • Displayed status information (prescription status, health insurance fund approval status)

Purpose: Informing the patient about the progress of the approval procedure with the statutory health insurance fund; transparency regarding the care process.

System: The status query is made against the care systems described in Section 6.5 (Kumavision). Only data that is already being processed as part of the ongoing care is displayed.

Hosting: Germany (pursuant to Section 6.5).

Retention period: The query itself is not stored; the underlying care data is retained in accordance with Section 6.8.

Legal basis:

  • Art. 9(2)(h) GDPR in conjunction with § 22(1)(1)(b) BDSG (healthcare)
  • Art. 6(1)(b) GDPR (contract performance / pre-contractual measures)

Data security note: The status query is SSL/TLS encrypted (see Section 4.2). The status query requires only the patient's insurance number. We recommend carrying out the status query only on private, secured devices.

Note for privately insured patients: Privately insured patients are contacted directly by their patient supervisor as soon as the prescription has been received by us. An online status query is not provided for this group.

7. Customer Portal (enovis-kundenportal.de)

Applicable to: https://enovis-kundenportal.de/de

7.1 Description and Purpose

The customer portal is the central communication and service offering for commercial customers in the DACH region. It comprises the following functional areas:

Area: Ordering

Functions included: Order by e-mail, EDI requests/information, General Terms and Conditions (T&Cs); webshop access (in preparation)


Area: Shipment information

Functions included: Shipment tracking of goods deliveries


Area: After-sales service

Functions included: Product complaints, product returns, repair requests, service & maintenance requests


Area: Accounting

Functions included: Invoice duplicates, invoice corrections, invoice delivery by e-mail


Area: Contact

Functions included: Field service map, service hotlines, contact requests, customer feedback


Area: Downloads

Functions included: Product information, documents, forms

Requests are recorded as tickets in the backend and forwarded to the responsible internal teams. An interface to Salesforce (SFDC) enables direct ticket creation by field service employees.

7.2 Operator and Hosting: BELPOLTEX B.V.

The customer portal is technically operated and hosted by BELPOLTEX B.V.

Provider: Belpoltex B.V., Grimbergsteenweg 105/4, 1853 Grimbergen, Belgium (represented by Maxime Witters).

Purpose: Provision of the customer portal; hosting of frontend and backend ticketing system; system and software maintenance; data storage and processing.

Hosting: European Union (EU) – no transfer of personal data to third countries.

Safeguards: DPA pursuant to Art. 28 GDPR.

7.3 Data Processed in the Customer Portal

  • Company and customer data (company name, customer number)
  • Personal data of contact persons (first and last name, function)
  • Contact data (e-mail address, telephone number)
  • Address and delivery data (billing address, delivery address where different)
  • Order-related data (article number, serial number, error description, complaint reason, invoice number, product photos where applicable for complaints)
  • Usage and connection data (IP address, page views, click behaviour, session duration, device information, source)

7.4 Legal Bases

  • Art. 6(1)(b) GDPR (contract performance / processing of service requests)
  • Art. 6(1)(c) GDPR (legal obligations, in particular MDR / MPDG for complaints)
  • Art. 6(1)(f) GDPR (legitimate interest in efficient customer communication)

7.5 Salesforce – CRM, Sales and Marketing

We use Salesforce as the central system for customer relationship management, sales management and marketing communication.

Provider: Salesforce.com, Inc., Salesforce Tower, 415 Mission Street, San Francisco, CA 94105, USA.

Hosting: USA.

Safeguards: DPF certification (EU-US Data Privacy Framework); SCC pursuant to Art. 46 GDPR; DPA pursuant to Art. 28 GDPR. See Section 1.4.

Note: Only professional contact data is processed in Salesforce. Patient data, health data and prescription data are not processed in Salesforce at any time and remain exclusively in the German systems Kumavision and H-SAS (see Section 6.5).

7.5.1 Affected Groups of Persons

In Salesforce, we process professional contact and communication data of the following groups:

Commercial customers and business partners (B2B): Orthopaedic supply stores, clinics, purchasing associations and other business partners with whom a contractual or business relationship exists.

Prescribers and medical professionals: General practitioners, specialists and hospital doctors who prescribe or recommend products from our range. This covers all product categories of our company – from assistive devices on medical prescription to products recommended in the context of medical consultation (e.g. IGeL products). These persons have no direct contractual relationship with us; their professional contact data is processed exclusively in connection with maintaining professional relationships in the context of our business activities.

Emergency depot managers (medical practices and clinics): Medical practices, clinics and other medical facilities at which we provide assistive devices for immediate emergency care within the framework of a depot agreement. A contractual agreement (depot or consignment contract) exists with these facilities. The data processed in this context relates exclusively to the contact persons responsible for depot management at the respective facility, as well as depot and delivery-related data. Patient data is not processed in the context of emergency depot management.

7.5.2 Sales Cloud – CRM and Sales Management

Purpose:

  • Management of business contacts and customer relationships (B2B customers)
  • Maintenance of prescriber and specialist contacts for field service support and professional communication across all product categories
  • Management of emergency depot agreements: contact maintenance, stock monitoring, delivery planning and billing
  • Synchronisation of complaint and service data from the customer portal
  • Direct ticket creation by field service employees
  • Documentation of sales and communication processes

Data processed:

  • Professional contact data: first and last name, function / speciality, practice or company name, address, business e-mail address, telephone number
  • Communication and visit history (field service)
  • Depot-related data: depot location, stock data, delivery history, device data (serial numbers, product categories)
  • Complaint and service data (for B2B customers)
  •  Sales-related transaction history

Retention period: For as long as the business, prescriber or depot relationship is active; in the absence of contact or upon termination of the relationship, 2 years, unless statutory retention obligations apply.

Legal bases:

  • Art. 6(1)(b) GDPR – contract performance for B2B customers, business partners and emergency depot contractual partners
  • Art. 6(1)(f) GDPR – legitimate interest in maintaining professional relationships with prescribers and medical professionals within the scope of our activities as a medical device provider, and in efficient sales management

7.5.3 Marketing Cloud Engagement – B2B Professional Communication

Purpose:

  • Sending professional e-mail communications to B2B customers, prescribers, medical professionals and depot managers (e.g. product information, care guidance, specialist information on new products, depot-relevant service updates)
  • Management of communication preferences and objections (opt-out)
  • Segmentation of target groups for targeted professional communication

Data processed:

  • Business e-mail address, name, function / speciality, company / practice / facility
  • Communication history (dispatch status, aggregated open and click behaviour)
  • Opt-out status and objection documentation

Legal bases:

  • Art. 6(1)(b) GDPR – contract performance for contractually bound depot partners (where communication serves the purpose of contract processing)
  • Art. 6(1)(f) GDPR (legitimate interest) for professional communication with: 

  1. B2B customers, where an ongoing or concluded business relationship exists (§ 7(3) UWG)
  2. Prescribers and medical professionals, where communication has a direct professional connection to our products and services, the recipient is addressed in a professional capacity and no objection has been lodged

  • Art. 6(1)(a) GDPR (consent) for recipients who have expressly consented to receiving communications

Right to object / opt-out: You may object to the processing of your data for communication purposes at any time – via the unsubscribe link in each e-mail or by contacting our Data Protection Officer (see Section 1.3). Objections are implemented immediately and documented permanently.

Retention period: Active contact data for as long as the relationship exists, thereafter or in the absence of contact 2 years; opt-out documentation beyond this permanently to ensure the effect of the objection.

E-mail sending service – Maileon: We carry out the technical e-mail dispatch as well as the management and permanent documentation of opt-outs and objections via Maileon.

Provider: XQueue GmbH, Mainzer Landstrasse 68, 60325 Frankfurt am Main

Hosting: Germany

Data processed: Business e-mail address, name (where included in dispatch), dispatch status, delivery confirmations, bounce information, opt-out status and timestamp

Safeguards: DPA pursuant to Art. 28 GDPR (in place); no third-country transfer

Retention period: Dispatch data (delivery status, bounce information): 6 months after dispatch; opt-out documentation: permanently to ensure the effect of the objection.

7.6 Product Complaints and MDR Reporting Obligations

Data from product complaints is also processed to fulfil our reporting obligations under MDR (EU 2017/745) and MPDG and may necessitate a report to the BfArM (Federal Institute for Pharmaceuticals and Medical Devices).

Legal basis: Art. 6(1)(c) GDPR.

7.7 Retention Periods – Customer Portal

Type of data: Complaint / repair documentation (MDR)

Retention period: At least 10 years after placing on the market


Type of data: Commercial / tax law documents

Retention period: 10 years (§ 147 AO, § 257 HGB)


Type of data: General service communication

Retention period: 6 years (§ 257 HGB)


Type of data: Usage and connection data

Retention period: In accordance with BELPOLTEX retention policies; maximum 30 days

8. Oracle EBS – B2B Order Processing

Applicable to: B2B order processing (internal)

For the commercial processing of B2B orders, we use Oracle E-Business Suite (Oracle EBS) as a group-wide SaaS solution of the Enovis Group.

Provider: Oracle Corporation (via Enovis Group framework agreement).

Purpose: ERP-supported order processing, delivery and invoice management in the B2B area.

Data processed: Company and contact data of business partners, order, delivery and invoice data, product master data.

Patient data, health data and prescription data are not processed in Oracle EBS and remain exclusively in the German systems Kumavision and H-SAS.

Hosting: USA.

Safeguards: SCC pursuant to Art. 46(2)(c) GDPR; DPA pursuant to Art. 28 GDPR (via Enovis Group framework agreement). Note: Oracle EBS does not have its own DPF certification; safeguarding is provided exclusively via SCC and DPA. See Section 1.4.

Legal basis: Art. 6(1)(b) GDPR (contract performance / B2B order processing); Art. 6(1)(f) GDPR (legitimate interest in efficient order processing).

9. Cookies, Tracking and Consent Management

Applicable to: www.enovis-medtech.de and https://enovis-kundenportal.de/de

9.1 Principle: Consent before Tracking

Our websites use cookies and comparable tracking technologies. Pursuant to § 25(1) TDDDG, the storing of information on the end device is generally only permissible with prior active consent. The sole exception is technically strictly necessary cookies.

We use the certified consent management platform Usercentrics (see Section 9.2), which is displayed on the first visit to each of our websites – before non-necessary cookies are set – and awaits your decision.

9.2 Consent Management – Usercentrics

Applicable to: www.enovis-medtech.de and https://enovis-kundenportal.de/de

To obtain, document and manage your cookie consents, we use the consent management platform Usercentrics.

Provider: Usercentrics GmbH, Sendlinger Strasse 7, 80331 Munich, Germany.

Purpose: Obtaining and documenting consents pursuant to § 25 TDDDG and Art. 7 GDPR; management and proof of consents given and withdrawn; provision of the cookie banner.

Data processed: IP address (truncated), consent timestamp, consent status per cookie category, browser and device information, consent ID.

Hosting: Germany / EU

Retention period: Consent records 3 years (proof obligation Art. 7(1) GDPR)

Safeguards: DPA pursuant to Art. 28 GDPR; no third-country transfer

Legal basis: § 25(2) No. 2 TDDDG (consent cookie technically necessary); Art. 6(1)(c) GDPR (proof obligation Art. 7 GDPR); Art. 6(1)(f) GDPR (legitimate interest in legally compliant consent management)

9.3 Requirements for Consent

  • Opt-in: Only active consent qualifies as consent; no "continued browsing as consent"
  • Equal ease: Declining is equally easy as accepting
  • Informed: Purpose, duration and third-party recipients are communicated in the banner
  • No nudging: No subliminal influence towards consent
  • Withdrawal: At any time via the cookie settings in the website footer
  • Compliance with the prohibition of coupling: Consent not linked to use of the website

9.4 Cookie Categories

Cookie type: Technically necessary

Description: Session management, login status, language settings

Consent required: No

Legal Basis: Art. 6(1)(f) GDPR


Cookie type: Analytics (GA4)

Description: Usage statistics, behaviour analysis, conversion tracking

Consent required: Yes

Legal Basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG


Cookie type: Marketing

Description: Retargeting, personalised advertising (Google Ads)

Consent required: Yes

Legal Basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG

9.5 Google Analytics 4 (GA4)

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Purpose: Analysis of user behaviour, campaign measurement (SEA, SEO, newsletter, social media), landing page performance, BigQuery export / Power BI reporting (DACH).

Data processed: IP address (anonymised), user agent, page views, scroll depth, click and navigation behaviour, session duration, pseudonymised Google user ID / device ID, campaign data, coarse location information.

Technical safeguards: IP anonymisation activated; Google Consent Mode v2 implemented; GA4 loads exclusively after consent has been given; data retention period set to 2 months; reset of deletion cycle deactivated; no data sharing for Google services; no access for Account Specialists / benchmarking; no data enrichment; no user ID; no regional device data.

Google Signals / Google Ads: Activated only on the basis of marketing consent.

Hosting: EU / USA.

Safeguards: DPF certification; DPA pursuant to Art. 28 GDPR; DPIA carried out. See Section 1.4.

Legal bases: § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR (consent); third-country transfer on the basis of DPF certification (Art. 45 in conjunction with Art. 46 GDPR). See Section 1.4.

Withdrawal / opt-out: Withdrawable at any time via cookie settings (footer); additionally the browser plugin can be used: https://tools.google.com/dlpage/gaoptout; further information: https://policies.google.com/privacy

10. Newsletter

Applicable to: www.enovis-medtech.de

If you wish to receive the newsletter offered on our website, we require your e-mail address and confirmation of your consent (double opt-in procedure).

Data processed: E-mail address, name where applicable; confirmation record of consent.

Purpose: Dispatch of the newsletter to recipients who have consented to its receipt.

Retention period: Until cancellation of the newsletter subscription.

Legal basis: Art. 6(1)(a) GDPR (consent).

Withdrawal: At any time via the "unsubscribe" link in the newsletter. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.

11. Links to Social Media Platforms

Applicable to: www.enovis-medtech.de and https://enovis-kundenportal.de/de

Our websites contain icons in the footer with links to the following social media platforms:

  • YouTube (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA)
  • Facebook / Instagram (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland)
  • LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland)
  • Xing (New Work SE, Am Strandkai 1, 20457 Hamburg, Germany)

These icons are exclusively external hyperlinks. When you access our website, no data is transmitted to these platforms. Data processing by the respective platform only takes place when you actively click on the link and access the external platform. From that point on, the privacy policy of the respective platform applies – not this Privacy Policy.

We have no influence over the data processing by these platforms and recommend reading the respective privacy notices before using the platforms.

12. Overview of All Systems and Service Providers Used

This table provides a quick overview of all systems and service providers described in this Privacy Policy. For detailed information on individual systems, see the relevant sections:

Patient care: Section 6.5

B2B order processing: Section 8 

Customer portal: Sections 7.2 and 7.5 

Website operation: Sections 4.3, 5.2, 5.3, 9.2, 9.5, 11 

Customer portal operation: Sections 4.4, 7.2, 9.2

Employees & applicants: Sections 13.3 and 14.2 

Telephony & call centre: Section 13.3.5

Third-country transfers: See Section 1.4 for safeguarding mechanisms. All processors have concluded a data processing agreement (DPA) pursuant to Art. 28 GDPR.

System / Service Provider: Kumavision AG

Scope: Patient care (Sections 6.5, 6.10)

Purpose: Care, GKV / private billing, online status query

Hosting: Germany (Azure DE)

Safeguards: DPA Art. 28 GDPR


System / Service Provider: M Assist GmbH

Scope: Patient care (Section 6.5)

Purpose: Support / customisation Kumavision

Hosting: Germany

Safeguards: DPA Art. 28 GDPR


System / Service Provider: H-SAS GmbH

Scope: Patient care (Section 6.5)

Purpose: Digital document capture

Hosting: Germany

Safeguards: DPA Art. 28 GDPR


System / Service Provider: FTAPI Software GmbH

Scope: Patient care (Sections 6.1, 6.4, 6.5)

Purpose: Secure data transmission inbound (prescribers / orthopaedic supply stores) and outbound (patient supervisors); end-to-end encryption

Hosting: Germany

Safeguards: DPA Art. 28 GDPR; no third-country transfer


System / Service Provider: RZH (data centre)

Scope: Patient care (Section 6.5)

Purpose: GKV billing § 302 SGB V

Hosting: Germany

Safeguards: DPA Art. 28 GDPR


System / Service Provider: Vercel Inc.

Scope: Website operation (Section 4.3) – www.enovis-medtech.de

Purpose: Web hosting main website

Hosting: USA (global CDN)

Safeguards: DPF + SCC + DPA Art. 28 GDPR


System / Service Provider: BELPOLTEX B.V

Scope: Customer portal (Section 7.2)

Purpose: Hosting & operation portal + ticketing system

Hosting: EU (Belgium)

Safeguards: DPA Art. 28 GDPR


System / Service Provider: Usercentrics GmbH

Scope: Main website (Section 9.2); Customer portal (Section 9.2)

Purpose: Cookie consent management (CMP)

Hosting: Germany

Safeguards: DPA Art. 28 GDPR; no third-country transfer


System / Service Provider: Salesforce Sales Cloud

Scope: CRM / sales / emergency depots (Section 7.5.2)

Purpose: CRM, contact maintenance B2B customers, prescribers, medical staff and depot managers

Hosting: USA

Safeguards: DPF + SCC + DPA Art. 28 GDPR


System / Service Provider: Salesforce Marketing Cloud Engagement

Scope: B2B professional communication (Section 7.5.3)

Purpose: E-mail professional communication, opt-out management

Hosting: USA

Safeguards: DPF + SCC + DPA Art. 28 GDPR


System / Service Provider: Maileon (XQueue GmbH)

Scope: B2B professional communication (Section 7.5.3)

Purpose: E-mail dispatch, opt-out documentation

Hosting: Germany

Safeguards:DPA Art. 28 GDPR; no third-country transfer


System / Service Provider: Cloudflare, Inc.

Scope: Customer portal (Section 4.4)

Purpose: WAF, bot detection, DDoS protection

Hosting: USA (EU PoPs)

Safeguards: DPF + SCC + DPA Art. 28 GDPR


System / Service Provider: Google Analytics 4

Scope: Both websites (Section 9.5)

Purpose: Web analytics, marketing campaign measurement

Hosting: EU / USA

Safeguards: Consent + DPF + DPA Art. 28 GDPR


System / Service Provider: Google reCAPTCHA

Scope: Main website (Section 5.2)

Purpose: Bot protection for forms

Hosting: USA

Safeguards: Consent + DPF + DPA Art. 28 GDPR


System / Service Provider: Lime Connect (Userlike)

Scope: Main website (Section 5.3)

Purpose: Chat widget, live chat, contact

Hosting: Germany

Safeguards: DPA Art. 28 GDPR; no third-country transfer


System / Service Provider: Workday, Inc.

Scope: Employees & applicants (Sections 13.3.1, 14.2)

Purpose: HR management, recruiting

Hosting: USA

Safeguards: DPF + SCC + DPA Art. 28 GDPR


System / Service Provider: DATEV eG

Scope: Employees (Section 13.3.2)

Purpose: Payroll accounting

Hosting: Germany

Safeguards: DPA Art. 28 GDPR


System / Service Provider: GFOS mbH

Scope: Employees (Section 13.3.3)

Purpose: Time recording, absence management

Hosting: Germany

Safeguards: DPA Art. 28 GDPR


System / Service Provider: AON

Scope: Employees (Section 13.3.4)

Purpose: Occupational pension, insurance management

Hosting: Germany

Safeguards: DPA Art. 28 GDPR


System / Service Provider: RingCentral Germany GmbH

Scope: Telephony – employees & customers (Section 13.3.5)

Purpose: Company-wide voice communication SIP telephony

Hosting: Germany (EU)

Safeguards: DPA Art. 28 GDPR; DPF (parent company RingCentral, Inc.)


System / Service Provider: RingCentral France SAS / NICE

Scope: Call centre – employees & customers (Section 13.3.5)

Purpose: Intelligent call distribution, IVR, service management

Hosting: France (EU)

Safeguards: DPA Art. 28 GDPR; adequacy decision Israel Art. 45 GDPR (NICE Ltd.)


System / Service Provider: Microsoft 365

Scope: Employees & B2B partners (Section 13.3.6)

Purpose: Productivity and communication platform

Hosting: EU (EU Data Boundary)

Safeguards: DPF + SCC + DPA Art. 28 GDPR

13. Data Protection for Employees

Applicable to: all current employees

13.1 Purpose and Legal Bases

We process personal data of our employees for the purpose of establishing, performing and terminating the employment relationship and for fulfilling legal obligations.

Legal bases:

  • § 26 BDSG in conjunction with Art. 88 GDPR (employee data protection)
  • Art. 6(1)(b) GDPR (performance of the employment contract)
  • Art. 6(1)(c) GDPR (legal obligations: tax, social security, employment law)
  • Art. 6(1)(f) GDPR (legitimate interest: IT security, company organisation)
  • Art. 6(1)(a) GDPR (consent for voluntarily provided additional data)

13.2 Categories of Data Processed

Mandatory stored data:

Data category: Master data

Examples: First and last name, date of birth, place of residence


Data category: Contact data

Examples: Private telephone number, e-mail address where applicable


Data category: Contract data

Examples: Start date, function / position, remuneration, working hours, fixed-term status


Data category: Organisational data

Examples: Cost centre, line manager, location, department


Data category: Tax / social security data

Examples: Tax class, tax ID, social security number, health insurance fund


Data category: Bank data

Examples: Bank account details for salary payment

Voluntarily providable data (career planning in Workday): Employees may additionally store voluntary further information (qualification certificates, language skills, competencies, career goals, mentoring preferences, other profile information).

Important note: Voluntary information is provided on the basis of your consent (Art. 6(1)(a) GDPR). No disadvantages arise for the employment relationship from not providing such information. Information on special categories of personal data (Art. 9 GDPR) requires explicit consent, which is obtained separately.

13.3 Systems Used

13.3.1 Workday – HR Information System

In Workday, employee appraisals, performance reviews (including 360° feedback), career planning and target agreements as well as master and contract data management are digitally supported. Access is role-based and restricted to what is required.

Provider: Workday, Inc., 6110 Stoneridge Mall Road, Pleasanton, CA 94588, USA.

Data processed: Master data, contact data, contract data, organisational data, tax / social security data, bank data, voluntarily provided additional data (qualifications, competencies, career goals).

Purpose: Personnel management, performance appraisal, career planning, contract performance.

Hosting: USA.

Safeguards: DPF certification; SCC pursuant to Art. 46 GDPR; DPA pursuant to Art. 28 GDPR. See Section 1.4.

Retention period: During the employment relationship and beyond in accordance with statutory retention obligations.

Legal basis:

  • Art. 6(1)(b) GDPR (contract performance)
  • Art. 6(1)(a) GDPR (consent for voluntary additional data)
  • Art. 6(1)(c) GDPR (legal obligations: tax, social security law)

13.3.2 Payroll and Financial Accounting (DATEV)

Provider: DATEV eG, Paumgartnerstrasse 6–14, 90429 Nürnberg.

Data processed: Master data, tax ID, social security number, salary data, bank account details

Purpose: Preparation and processing of payroll accounting, fulfilment of tax and social security obligations

Hosting: Germany and EU

Safeguards: DPA pursuant to Art. 28 GDPR; no third-country transfer.

Retention period: 10 years (pursuant to § 147 AO, § 257 HGB)

Legal basis:

  • Art. 6(1)(b) and (c) GDPR
  • § 26(1) BDSG

13.3.3 Time Recording and Absence Management (GFOS)

Provider: GFOS mbH, Cathostrasse 5, 45356 Essen.

Data processed: Name, date of birth, department, working hours, holiday data, absence data

Purpose: Recording of working hours, management of absences (holiday, illness), personnel management

Hosting: Germany

Safeguards: DPA pursuant to Art. 28 GDPR; no third-country transfer.

Retention period: 10 years (pursuant to § 147 AO, § 257 HGB)

Legal basis:

  • Art. 6(1)(b) and (c) GDPR
  • § 16(2) ArbZG (working time recording obligation)
  • § 26(1) BDSG

13.3.4 Occupational Pension and Insurance Management (AON)

Provider: AON (contractual partner pursuant to Enovis Group framework agreement).

Data processed:

  • Personal master data (name, date of birth, address)
  • Service period data (start, end, career)
  • Salary and pension data
  • Bank account details
  • Health data where applicable for insurance application (with explicit consent)

Persons affected: Employees, pensioners, former employees, surviving dependants (widows/orphans), persons entitled to pension equalisation

Purpose: Management of insurance policies and occupational pension; processing of insurance applications; pension management and claims processing

Hosting: Germany

Retention period: During the insurance relationship; 10 years after termination for archiving purposes.

Legal basis:

  • Art. 6(1)(b) and (c) GDPR
  • Art. 9(2)(a) GDPR (explicit consent for health data)
  • § 26(1) BDSG

13.3.5 Telephony and Call Centre Software – RingCentral & NICE

Applicable to: all employees and customers who contact us by telephone

For our corporate communication and telephone customer service, we use two integrated systems:

  • RingCentral – as the group-wide telephone system with SIP telephony
  • NICE – as call centre software for intelligent call distribution and service management

Both systems are integrated via a group-wide framework agreement (Master Services Agreement) between RingCentral, Inc. and the Enovis Group parent company.

13.3.5.1 RingCentral – Telephone System

Provider (operational): RingCentral Germany GmbH, Caffamacherreihe 7, 20355 Hamburg, Germany

Parent company: RingCentral, Inc., 20 Davis Drive, Belmont, CA 94002, USA

Data processed:

  • Telephone numbers (internal and external)
  • Connection data (time, duration, call direction)
  • Device IDs and network data (for QoS monitoring)

Purpose:

  • Provision of company-wide voice communication (internal and external)
  • Availability for customers, partners and service providers
  • Technical quality monitoring of connection quality (QoS reporting)
  • Seamless device switching during active calls (call flip) 

Functions not used: AI-based call evaluation, Agent Assist, virtual assistants, CRM integration, Microsoft Teams integration, call recording.

Hosting: Germany (EU)

Safeguards: DPA pursuant to Art. 28 GDPR with RingCentral Germany GmbH; RingCentral, Inc. is DPF-certified. Operational contractual partner is a German company in the EEA.

Retention period: Connection data for a maximum of 6 months, unless a statutory obligation to retain for longer applies.

Legal basis:

  • Art. 6(1)(b) GDPR (contract performance / communication with customers and partners)
  • Art. 6(1)(f) GDPR (legitimate interest in functional and secure corporate communication)

13.3.5.2 NICE – Call Centre Software

Provider (operational): RingCentral France SAS, 6 Cité de Londres, 75009 Paris, France

Software manufacturer: NICE Ltd., 13 Zarchin Street, Ra'anana, Israel

Data processed:

  • Telephone numbers and connection data of callers
  • Call details: time, duration, routing information, waiting time
  • Department selection (Interactive Voice Response (IVR) inputs)
  • Aggregated, anonymised performance metrics of employees (KPIs)

Purpose:

  • Intelligent distribution of incoming calls to available employees (ACD / routing)
  • Pre-qualification of calls via interactive voice response (IVR)
  • Management of queues and time-based forwarding
  • Measurement of service quality through aggregated, anonymised metrics

Functions not used: Call recording, voice analysis, sentiment analysis, omnichannel functions (chat, e-mail, social media), real-time adherence (individual employee monitoring), scorecards, AI-based content analysis. There is no monitoring function for supervisors and no room surveillance function.

Hosting: France (EU)

Safeguards: DPA pursuant to Art. 28 GDPR with RingCentral France SAS; NICE Ltd. (Israel) is subject to the EU adequacy decision pursuant to Art. 45 GDPR.

Retention period: Connection and routing data maximum 30 days; aggregated metrics are anonymised and are not subject to a personal retention period.

Legal basis:

  • Art. 6(1)(b) GDPR (contract performance / processing of customer enquiries)
  • Art. 6(1)(f) GDPR (legitimate interest in efficient availability and service quality)

Data protection for employees: All performance data is collected exclusively in aggregated and anonymised form. Individual performance monitoring of individual employees does not take place. Processing is carried out in accordance with § 26 BDSG and any existing works agreements.

13.3.6 Microsoft 365 – Productivity and Communication Platform

Applicable to: all employees and, in the B2B context, external interlocutors

We use Microsoft 365 (M365) as the group-wide productivity and communication platform. Licensing is via a group-wide framework agreement of the Enovis Group. Among the services used are:

  • Communication: Outlook (e-mail), Microsoft Teams (video conferences, chat, telephony)
  • Productivity: Word, Excel, PowerPoint, OneNote
  • Collaboration: SharePoint, Teams channels, Loop, Planner
  • AI support: Microsoft Copilot (where licensed and activated)

Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland

Parent company: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA

Data processed:

Category: Communication data

Examples: E-mail addresses, message content, call metadata


Category: Connection data

Examples: Time, duration, participants of meetings and calls


Category: Content data

Examples: Documents, tables, presentations, notes, planning entries


Category: Usage data

Examples: Login times, applications used, activity logs


Category: Teams recordings

Examples: Recordings of meetings (where activated and all participants informed)


Category: Copilot data

Examples: Inputs and outputs when using AI functions (where activated)

Purpose:

  • Internal and external corporate communication (e-mail, chat, video conference)
  • Creation, editing and joint use of work documents
  • Project planning and task management
  • Conducting meetings and training sessions (internal and with B2B partners)
  • Support of work processes through AI functions (Microsoft Copilot, where activated)

Hosting: Microsoft EU Data Boundary – data is stored and processed exclusively in European data centres (EU / EEA).

Safeguards: DPA pursuant to Art. 28 GDPR (Microsoft Data Protection Addendum); SCC pursuant to Art. 46 GDPR for any transfers to the US parent company; DPF certification; group-wide framework agreement with activated EU Privacy Settings.

Retention period: Duration of the employment relationship or business relationship; after termination, data is deleted in accordance with the configured retention policies, at the latest however after expiry of the legally required retention periods (maximum 10 years for tax and commercial law relevant content).

Legal bases:

  • Art. 6(1)(b) GDPR – performance of the employment contract (for employees)
  • Art. 6(1)(f) GDPR – legitimate interest in efficient and secure corporate communication
  • Art. 6(1)(f) GDPR – legitimate interest in communication with external B2B contacts within existing business relationships
  • § 26 BDSG in conjunction with Art. 88 GDPR – employee data protection
  • Art. 6(1)(a) GDPR – consent for optional functions such as meeting recordings

Special notes:

Meeting recordings: Meetings in Microsoft Teams may be recorded at the instigation of the inviting employee. A recording takes place exclusively with the explicit consent of all participants at the beginning of the meeting. The recording remains in the area of responsibility of the inviting employee and is managed by them. No central retention period is set; the recording is to be deleted once the purpose has ceased.

Legal basis: Art. 6(1)(a) GDPR (consent).

Microsoft Copilot (AI functions): Where Microsoft Copilot is activated, inputs and context data are used for AI-supported processing. Microsoft processes this data exclusively for the provision of the service and not for training AI models (pursuant to the Microsoft Data Protection Addendum). Processing takes place within the EU Data Boundary.

External communication via Teams (B2B): Microsoft Teams is also used for communication with external B2B partners (customers, suppliers). Connection and communication data of external participants is processed in this context. External participants are informed about data processing at the beginning of a meeting.

No processing of patient data: Patient data, health data and prescription data are not processed via Microsoft 365 at any time and remain exclusively in the German systems Kumavision and H-SAS (see Section 6.5).

13.4 Data Sharing

13.4.1 Intra-Group Data Sharing

We are part of the Enovis Group. Employee data may be shared with other Enovis Group companies in the context of intra-group processes, in particular for organisational structure, personnel management and corporate talent development.

Safeguards: SCC pursuant to Art. 46(2)(c) GDPR; works agreements pursuant to Art. 88 GDPR in conjunction with § 26 BDSG.

Legal basis: Art. 6(1)(b) and (c) GDPR.

13.4.2 Sharing with External Processors

To fulfil our personnel administration, payroll, time management and insurance tasks, we work with specialised external processors (see Section 13.3). These process employee data only on our instructions and in compliance with strict data protection requirements pursuant to Art. 28 GDPR. Where data is transferred to third countries in this context (in particular Workday, USA – Section 13.3.1), this is done on the basis of the safeguarding mechanisms described in Section 1.4 (DPF, SCC, DPA).

13.4.3 Sharing with External Recipients Who Are Not Processors

In addition, we share employee data with the following external entities, which do not act as processors but as independent controllers within the meaning of Art. 4(7) GDPR:

Germany:

  • Tax authorities (tax office) – for payroll tax notifications
  • Social security providers and health insurance funds – for social security notifications
  • Trade association (Berufsgenossenschaft) – for accident insurance notifications
  • Benefit providers (pension insurance, employment agency where applicable) – for benefit processing

Legal basis: Art. 6(1)(c) GDPR (legal obligations pursuant to EStG, SGB IV, SGB X, ArbZG)

Austria:

For employees whose place of employment is in Austria, we engage a tax advisory firm or payroll office for the preparation of payroll accounts and the fulfilment of the associated tax and social security reporting obligations.

The engaged party acts in the exercise of its professional and legal obligations as an independent controller within the meaning of Art. 4(7) GDPR. It is subject to the Austrian Act on Tax Advisers (WTBG 2017) and the relevant data protection obligations, and processes the transmitted data exclusively within the scope of the legally provided purposes.

Data categories transmitted:

  • Master data (name, date of birth, address)
  • Tax data (tax class, tax ID / social security number)
  • Salary data, bank account details
  • Absence and working time data (where required for payroll)

Recipients of notifications (via the tax advisory office):

  • Austrian tax office (FinanzOnline) – for payroll tax notifications
  • Austrian social security providers (ÖGK, AUVA, PVA) – for social security notifications
  • Competent authorities under the Corporate Employee and Self-Employed Persons Provision Act (BMSVG) – for severance contributions

Legal basis: Art. 6(1)(c) GDPR in conjunction with the relevant Austrian legal provisions, in particular:

  • Federal Fiscal Code (Bundesabgabenordnung / BAO)
  • General Social Insurance Act (Allgemeines Sozialversicherungsgesetz / ASVG)
  • Income Tax Act (Einkommensteuergesetz / EStG) in conjunction with payroll tax guidelines
  • Corporate Employee and Self-Employed Persons Provision Act (BMSVG)

13.5 Retention Periods – Employee Data

The retention period for employee data depends on the purpose of the processing and applicable laws:

Type of data: Payroll documents

Retention period: 10 years

Legal Basis: § 147 AO


Type of data: Personnel files (general)

Retention period: 10 years after termination

Legal Basis: § 147 AO, § 257 HGB


Type of data: Tax / social security documents

Retention period: 10 years

Legal Basis: § 147 AO


Type of data: Employment references

Retention period: Employment references

Legal Basis: Limitation law


Type of data: Voluntary career data

Retention period: Until withdrawal or termination of employment

Legal Basis: Art. 7(3) GDPR


Type of data: Employee appraisals / performance reviews

Retention period: During the employment relationship; after termination up to 3 years; where tax or commercial law relevant up to 10 years

Legal Basis: § 195 BGB, § 61b ArbGG; where applicable § 147 AO, § 257 HGB; § 26 BDSG


Type of data: Time recording and absence data

Retention period: 10 years

Legal Basis: § 147 AO, § 257 HGB


Type of data: Pension / retirement provision data

Retention period: 10 years after termination of the insurance relationship

Legal Basis: Contractual provisions, Art. 28 GDPR


Type of data: Telephony connection data (RingCentral)

Retention period: Maximum 6 months

Legal Basis: Statutory retention obligations


Type of data: Call centre routing data (NICE)

Retention period: Maximum 30 days

Legal Basis: Operational necessity


Type of data: Microsoft 365 – work data

Retention period: After termination of employment in accordance with retention policies; tax/commercial law relevant content maximum 10 years

Legal Basis: § 147 AO, § 257 HGB

Note: Statutory retention obligations remain unaffected and may necessitate longer retention. After expiry of the retention periods, your data will be deleted or anonymised.

14. Data Protection for Applicants

Applicable to: all persons who apply to us

14.1 Purpose and Legal Bases

We process personal data of applicants exclusively for the purpose of carrying out the application procedure and deciding on the establishment of an employment relationship.

Legal bases:

  • § 26(1) BDSG in conjunction with Art. 88 GDPR
  • Art. 6(1)(b) GDPR (pre-contractual measures)

14.2 Application Channel: Workday

Applicants upload their documents directly to Workday.

Provider: Workday, Inc., 6110 Stoneridge Mall Road, Pleasanton, CA 94588, USA.

Data processed: Master data (name, date of birth), contact data (address, e-mail, telephone), application documents (CV, cover letter, certificates, qualifications), information on professional experience and education, salary expectations, earliest possible start date, information on work permit and immigration requirements where applicable, previous group affiliation, internal interview notes and evaluations.

Purpose: Carrying out the application procedure and deciding on the establishment of an employment relationship.

Hosting: USA.

Safeguards: DPF certification; SCC pursuant to Art. 46 GDPR; DPA pursuant to Art. 28 GDPR. See Section 1.4.

Note on special categories (Art. 9 GDPR): We ask that information on health, disability or similar characteristics only be provided if you expressly wish to do so.

14.3 Further Application Channels

Application by e-mail: Incoming application documents are reviewed by our HR team and then manually entered into Workday.

Application by post: Incoming documents are reviewed, scanned and manually entered into Workday. Upon request, we will return your documents or destroy them in accordance with our retention periods.

Recipients of application data: The entities required for decision-making, where applicable within the Group, e.g. HR, specialist department, legal department where applicable, IT and works council.

14.4 Headhunters and External Recruitment Agencies

DPAs pursuant to Art. 28 GDPR exist with instructed headhunters acting on our behalf. Independently responsible recruiting partners (e.g. job portals) are themselves responsible under data protection law. Applicants referred via headhunters are informed by us upon receipt of their data.

14.5 Third-Country Transfer and Intra-Group Sharing

Workday is DPF-certified; SCC and a DPA pursuant to Art. 28 GDPR are in place. Intra-group sharing is based on SCC and, where applicable, works agreements. See Section 1.4 for further information on third-country transfers.

14.6 Retention Periods – Applicant Data

Situation: Rejection / no contract concluded

Retention period: 6 months after completion of the procedure (§ 15(4) in conjunction with (1) AGG, § 22 AGG, § 61b(1) ArbGG)

Situation: Hiring

Retention period: Employee data pursuant to Section 13.5

15. Your Rights as a Data Subject

You have the following rights under the GDPR. For all enquiries and requests, please contact our Data Protection Officer (see Section 1.3).

15.1 Right of Access (Art. 15 GDPR)

You have the right to obtain from us confirmation as to whether personal data concerning you is being processed, and if so, access to that data. You may obtain free information about which data we store about you, where it originates, for what purposes we process it and to whom we disclose it.

15.2 Right to Rectification (Art. 16 GDPR)

You have the right to request the rectification of inaccurate or incomplete personal data. Should you find that data stored about you with us is inaccurate or incomplete, you may ask us to correct it.

15.3 Right to Erasure – "Right to be Forgotten" (Art. 17 GDPR)

You have the right to request that personal data concerning you be erased, in particular where:

  • the data is no longer necessary for the purposes for which it was collected,
  • you have withdrawn your consent and there is no other legal basis for the processing,
  • you have objected to the processing,
  • the data has been unlawfully processed,
  • erasure is necessary to fulfil a legal obligation.

Exceptions: Erasure is not possible where the data is required to fulfil statutory retention obligations (e.g. tax and commercial law).

15.4 Right to Restriction of Processing (Art. 18 GDPR)

You have the right to request restriction of the processing of your personal data where:

  1. Accuracy contested: You contest the accuracy of your personal data stored with us. For the duration of the review, you have the right to request restriction of processing.
  2. Unlawful processing: The processing of your data is unlawful and you request restriction of use instead of erasure.
  3. Data required for legal claims: We no longer need your data, but you need it for the establishment, exercise or defence of legal claims.
  4. Objection lodged: You have lodged an objection pursuant to Art. 21(1) GDPR and it has not yet been determined whether our legitimate grounds override your interests.

Where processing has been restricted, such data may – apart from being stored – only be processed with your consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the EU or a Member State.

15.5 Right to Data Portability (Art. 20 GDPR)

You have the right to receive the personal data concerning you that you have provided to us, in a structured, commonly used and machine-readable format, and to transmit that data to another controller without obstruction from us.

Scope: This right applies to data processed on the basis of consent (Art. 6(1)(a) GDPR) or a contract (Art. 6(1)(b) GDPR).

15.6 Right to Object (Art. 21 GDPR)

Objection in special circumstances (Art. 21(1) GDPR)

Where we process your personal data on the basis of Art. 6(1)(e) or (f) GDPR (public interest or legitimate interest), you have the right at any time to object to that processing on grounds relating to your particular situation. This also applies to profiling based on those provisions. After an objection, we will no longer process your data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Objection to direct marketing (Art. 21(2) GDPR)

Where your personal data is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing; this also applies to profiling to the extent that it is related to such direct marketing. Upon objection, your data will no longer be used for the purposes of direct marketing.

15.7 Withdrawal of Consent (Art. 7(3) GDPR)

Many data processing operations are only possible with your explicit consent. You may withdraw consent already given at any time with effect for the future.

How to withdraw:

  • By e-mail: Send an informal e-mail to datenschutzbeauftragter@enovis.com with the subject line "Withdrawal of consent" and state which consent you wish to withdraw
  • By post: Write to the address of our Data Protection Officer stated above
  • Cookie settings: For cookies, withdrawal can be made at any time via the cookie settings in the footer of our website

The lawfulness of data processing carried out up to the point of withdrawal remains unaffected.

15.8 Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data infringes the GDPR. Further information on the complaints procedure can be found in Section 16.

16. Complaints Procedure and Contact with the Supervisory Authority

16.1 Internal Complaints Procedure

Should you consider that we have violated data protection provisions, you may first contact our Data Protection Officer directly (see Section 1.3).

Our complaints procedure:

  1. Submission: Direct your complaint by e-mail or post to the Data Protection Officer (see Section 1.3).
  2. Confirmation: We will confirm receipt of your complaint without undue delay.
  3. Processing: We will process your complaint promptly, at the latest within 30 days, and inform you of the outcome.
  4. Further steps: Should you be dissatisfied with our handling, you may contact the supervisory authority (see Section 16.2).

16.2 Complaint with the Supervisory Authority

If you are dissatisfied with our handling or we do not respond, you have the right to contact the competent supervisory authority:

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW)

P.O. Box 10 29 32 

70025 Stuttgart

Telephone:  +49 (0)711 615541-0 

Fax: +49 (0)711 61 55 41 15 

E-Mail: poststelle@lfdi.bwl.de 

Web: www.lfdi.bwl.de

A complaint with the supervisory authority is free of charge and may also be lodged without prior complaint to us.

17. Final Notes

17.1 Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy at any time with effect for the future. A current version is available on our website at all times. Should material changes be made, we will inform you separately where required.

17.2 Status of this Privacy Policy

Last updated: May 2026

Version: 13

Ormed GmbH | Bötzinger Strasse 90 | 79111 Freiburg 

Telephone: +49 (0)761 456601 | E-Mail: kundenservice@enovis.com | Web: www.enovis-medtech.de