Privacy Policy
Ormed GmbH | Bötzinger Str. 90 | 79111 Freiburg
Telephone: +49 761 456601 | E-Mail: kundenservice@enovis.com | Web: www.enovis-medtech.de
Privacy at a Glance
This Privacy Policy applies to all our online presences as well as to the processing of personal data of our patients, employees and applicants.
What happens to your data?
Personal data is any data by which you can be personally identified. We collect and process such data only to the extent permitted by law or with your consent. Some data is collected automatically when you visit our websites (technical data such as IP address, browser, time). Other data is provided directly by you, for example via contact forms.
Note on internet security: Please note that data transmission over the internet (e.g. when communicating by e-mail) may have security vulnerabilities. Complete protection of data from access by third parties is not possible.
What rights do you have?
You have the right at any time to receive free information about the origin, recipient and purpose of your stored personal data, as well as the right to rectification, restriction or deletion of this data. You also have the right to lodge a complaint with the competent supervisory authority. For detailed information on your rights, see Section 15.
Scope: Main Website
Address / Context https://www.enovis-medtech.de
Target Group: All visitors, patients, specialist audience
Scope: Customer Portal
Address / Context: https://enovis-kundenportal.de/de
Target Group: B2B specialist partners (orthopaedic supply stores, clinics, medical practices)
Scope: Patient care
Address / Context: Care process
Target Group: Treated patients
Scope: Employees
Address / Context: Employment relationship
Target Group: Current employees
Scope: Applicants
Address / Context: Application process
Target Group: Applicants
1. Controller and Data Protection Officer
1.1 Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) for all processing activities described in this declaration is:
Ormed GmbH
Bötzinger Straße 90
79111 Freiburg
Telephone: +49 (0)761 456601
E-Mail: kundenservice@enovis.com
Approved assistive device supplier pursuant to § 126 SGB V (German Social Code, Book V).
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
1.2 Data Protection Officer
As we regularly process special categories of personal data (in particular health data pursuant to Art. 9 GDPR), we are obliged pursuant to Art. 37 GDPR in conjunction with § 38 BDSG to appoint a Data Protection Officer and have designated Martin Möhrle as internal Data Protection Officer.
1.3 Central Contact Information
For all data protection enquiries, complaints and to withdraw consent, please contact our Data Protection Officer:
Martin Möhrle
Data Protection Officer of Ormed GmbH
Bötzinger Straße 90
79111 Freiburg
Telephone: +49 (0)761 4566131
E-Mail: datenschutzbeauftragter@enovis.com
Response time: All enquiries will be processed without undue delay, at the latest within 30 days.
Note: These contact details cover all processing activities described in this Privacy Policy. See also Sections 16 and 17 for further information on your rights and the complaints procedure.
1.4 Third-Country Transfers – Standard Safeguards
For certain processing operations, data is transferred to the USA and other third countries. These transfers are safeguarded by the following mechanisms:
EU-US Data Privacy Framework (DPF): Certification of the data recipient under the DPF
EU Standard Contractual Clauses (SCC): Contractual clauses pursuant to Art. 46(2)(c) GDPR
Data Processing Agreements (DPA): Agreements pursuant to Art. 28 GDPR for processors
Works Agreements: Agreements pursuant to Art. 88 GDPR in conjunction with § 26 BDSG
Residual risk: Despite these safeguards, a theoretical residual risk of government access to data in the USA (CLOUD Act) exists. This risk has been assessed and consciously accepted.
Note on the combination of DPF and SCC: Where providers are both DPF-certified and have concluded EU Standard Contractual Clauses (SCC), the SCC serve as a fallback in the event that DPF certification lapses or is suspended (cf. Privacy Shield, invalid since Schrems II, CJEU C-311/18). Maintaining both mechanisms in parallel reflects the principle of accountability and legal certainty (Art. 5(2) GDPR). For employee data (Workday), cumulative safeguarding through DPF and SCC is additionally recommended under data protection law, as the DPF does not explicitly address employee data protection pursuant to Art. 88 GDPR in conjunction with § 26 BDSG.
Specific applications:
See Sections
4.3 (Vercel – web hosting main website, USA),
4.4 (Cloudflare – WAF / DDoS protection customer portal, USA),
5.2 (Google reCAPTCHA – bot protection forms, USA),
7.5 (Salesforce – CRM / sales / marketing, USA),
8 (Oracle EBS – B2B order processing, USA),
9.5 (Google Analytics 4 – web analytics / campaign measurement, USA),
13.3.1 (Workday – HR system for employees, USA),
13.3.5 (RingCentral – telephony, USA / NICE call centre software, Israel),
14.2 (Workday – applicant management, USA).
Note: Patient and health data are NOT transferred to third countries (see Sections 3 and 6.5).
2. Group Affiliation (Enovis)
We are part of the Enovis Group (Enovis Corporation, 2711 Centerville Road, Wilmington, Delaware 19808, USA). In addition to our own products, we also distribute products that have been approved across the Enovis Group.
Intra-group data transfers occur:
- in the B2B context via Oracle EBS (order processing in Section 8)
- in the employment context via Workday (personnel management for employees in Section 13.3.1, for applicants in Section 14.2)
Third-country transfers to the USA are based on the safeguarding mechanisms described in Section 1.4.
Patient data and health data are not transferred to intra-group entities or to third countries at any time. They remain exclusively in the systems hosted in Germany (Section 6.5).
3. Special Features of Data Processing in the Healthcare Sector
As an approved assistive device supplier for CPM (Continuous Passive Motion) devices pursuant to § 126 SGB V, we process health data within the meaning of Art. 4(15) in conjunction with Art. 9 GDPR in the course of our care activities. Such data is subject to particularly strict legal protection.
Legal bases for health data:
- Art. 9(2)(h) GDPR in conjunction with § 22(1)(1)(b) BDSG (healthcare and billing)
- Art. 9(2)(i) GDPR (quality and safety standards in healthcare and medical devices)
- Art. 9(2)(a) GDPR (explicit consent, in particular for self-paying patients)
- Art. 6(1)(c) GDPR (legal obligations, in particular § 302 SGB V, MDR, MPDG)
- §§ 67 et seq. SGB X (social data protection, where social data within the meaning of SGB X is processed)
Health data is processed and stored exclusively in Germany. No transfer to third countries takes place for this category of data.
4. Provision of the Websites and Server Log Files
Applicable to: www.enovis-medtech.de and https://enovis-kundenportal.de/de
4.1 Server Log Files
Each time our websites are accessed, the responsible hosting or infrastructure provider automatically collects information in so-called server log files containing information that your browser transmits automatically:
Data processed:
- IP address of the accessing device
- Date and time of access
- URL accessed and data volume transmitted
- Browser type and version, operating system
- Referrer URL (source page)
These data are not merged with other data sources.
Purpose: Technical provision of the website, error analysis, IT security.
Retention period: The retention period depends on the system used. Unless a different period is specified for the systems listed by us, a standard retention period of 7 days applies, after which automatic deletion occurs.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technically sound presentation and optimisation of the website).
4.2 SSL / TLS Encryption
Our websites use SSL or TLS encryption for security reasons and to protect the transmission of confidential content. You can recognise an encrypted connection by the fact that the browser address bar changes from "http://" to "https://" and by the padlock symbol in the browser bar.
Purpose: Protection of data transmission against unauthorised access.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security).
4.3 Web Hosting – Main Website www.enovis-medtech.de
Our main website is operated on servers of an external hosting service provider. Each time the website is accessed, technical connection data is processed on the provider's servers; this is technically necessary for the operation of the website.
Provider: Vercel Inc. Address: 440 N Barranca Ave #4133, Covina, CA 91723, USA
Purpose: Technical operation and provision of the website www.enovis-medtech.de; storage of website files and static assets.
Data processed: IP address, connection metadata (time, duration, data volume), server logs (see also Section 4.1).
Hosting: Global CDN – primarily USA, EU nodes available
Retention period: In accordance with Vercel's retention policies; maximum 30 days; no further personal storage by the hosting provider beyond this period.
Safeguards: DPF certification (EU-US Data Privacy Framework); SCC (EU Standard Contractual Clauses, Art. 46 GDPR); DPA pursuant to Art. 28 GDPR.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technically sound provision of the website).
4.4 Protection against Automated Access – Cloudflare
Applicable to: https://enovis-kundenportal.de/de
All incoming traffic is processed by Cloudflare to protect against bot attacks and abusive access.
Provider: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA.
Purpose:
- Web Application Firewall (WAF)
- Bot detection and defence
- DDoS protection
- Protection against automated attacks
Data processed:
- IP address
- HTTP headers
- Request metadata
- Bot detection signals
Technical safeguards:
- Cloudflare processes data in real time for threat detection
- Legitimate requests are passed through
- Suspicious requests are blocked or subjected to a CAPTCHA check
Retention period: 30 days (log data for analysis purposes).
Safeguards: DPF certification (EU-US Data Privacy Framework); SCC (EU Standard Contractual Clauses, Art. 46 GDPR); DPA pursuant to Art. 28 GDPR.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security and protection against cyberattacks); where Cloudflare sets technically necessary cookies: § 25(2) No. 2 TDDDG.
Further information: https://www.cloudflare.com/privacypolicy/
5. Contact Form and General Enquiries
Applicable to: www.enovis-medtech.de and https://enovis-kundenportal.de/de
5.1 Contact Form and E-Mail Contact
If you contact us via contact forms, by e-mail or telephone, we process the data you submit exclusively to handle your enquiry. For service requests via the customer portal (ticketing system), Section 7 additionally applies.
Data processed:
- Name, e-mail address, telephone number where applicable
- Content of your message and any attached documents
- Where health-related: explicit consent pursuant to Art. 9(2)(a) GDPR
Purpose: Processing and responding to your enquiry.
Retention period: Until your enquiry has been fully processed, generally no longer than 6 months; statutory retention obligations (in particular § 257 HGB: 6 years for business correspondence) remain unaffected and may necessitate longer retention.
Legal basis: Art. 6(1)(b) and (f) GDPR; for health data additionally Art. 9(2)(a) GDPR.
We do not pass on this data without your consent.
5.2 Google reCAPTCHA
Applicable to: www.enovis-medtech.de
To protect our forms against abusive automated access, we use Google reCAPTCHA (invisible).
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: To distinguish human input from automated access (bot protection).
Data processed: Your IP address (this is truncated within the EU/EEA and before transmission to the USA, IP masking active) and, where applicable, further signals required by Google. The IP address is not merged with other Google data.
Safeguards: DPF certification; DPA pursuant to Art. 28 GDPR. See Section 1.4.
Legal basis: § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR (consent).
Further information: https://policies.google.com/privacy
5.3 Chat Widget with Automated FAQ Responses and Direct Forwarding to Staff
Applicable to: www.enovis-medtech.de
On our website we use the chat and contact widget Lime Connect by the provider Userlike GmbH. It enables visitors to quickly obtain answers to frequently asked questions, submit contact requests, arrange appointments or enter into a live chat directly with one of our members of staff. Qualified answers are provided exclusively by our employees.
Provider: Lime Connect (Userlike) GmbH, Kölnturm, Im Mediapark 8, 50670 Cologne; Telephone: 0221-77268620; E-Mail: support@lime-connect.com.
Scope of functions:
- General FAQ / product information
- Forwarding contact requests to staff
- Appointment scheduling
- Live chat with real employees
- Conversation logging
Data processed:
- Contact data (where voluntarily provided): name, e-mail address, telephone number
- Chat content: text entries and conversation histories
- Connection data: IP address, time and duration of session, browser type, source page
- Session data: technical identification features of the chat session
Note on health data: The chat widget is not intended for entering health data or patient-related information. We expressly ask users not to enter any health data, diagnoses or prescription information via the chat. Should such data nonetheless be entered voluntarily, it will be used exclusively for processing the specific enquiry and not processed further. For questions concerning patient care, please contact us directly (see Section 1.3).
Consent: The chat widget is loaded automatically when our website is accessed and requests its own cookie consent before active use. Without confirmation of this consent, no chat content is processed. The chat widget is technically loaded prior to the confirmation of the general cookie banner (Usercentrics); only technically necessary connection data is transmitted at this stage. Processing of content only takes place after your explicit consent.
Withdrawal: The consent given can be withdrawn at any time by closing the chat window or by contacting our Data Protection Officer (see Section 1.3).
Hosting: Germany (provider based in Cologne).
Safeguards: DPA pursuant to Art. 28 GDPR in place; no data sharing with third-party systems; no third-country transfer.
Retention periods:
- Chat histories and conversation content: 14 days, then automatic deletion
- Connection data (technical): 7 days
Legal bases:
- Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG – consent for active chat use and cookie setting
- Art. 6(1)(f) GDPR – legitimate interest in the technical provision of the chat widget (pre-loading)
- Art. 6(1)(b) GDPR – where a user actively submits a specific contact or service request (pre-contractual measures at the request of the data subject)
6. Data Processing in the Context of Patient Care (CPM Devices)
Applicable to: all treated patients – regardless of cost bearer
Information for patients: This section fully describes how we process your data in the context of the provision of a CPM device – from the order placement by your medical practice or clinic through to the collection of the device and billing. Without providing your data, your individual care may not be possible.
6.1 Origin of Patient Data
We receive patient data through various channels – from commissioning entities as well as, in certain cases, directly from patients themselves.
Transmission by prescribers and orthopaedic supply stores (medical supply retailers): As a rule, we receive the data required for care from the entity initiating the care – i.e. the prescribing medical practice, clinic or cooperating orthopaedic supply store. These entities act in coordination with the patients to enable the medically prescribed assistive device supply.
Categories of transmitting entities:
- Prescribing medical practices and specialists (in particular orthopaedics, surgery, trauma surgery)
- Clinics and hospitals (inpatient and post-inpatient care)
- Orthopaedic supply stores (as cooperating service providers)
- Health insurance funds and other cost bearers (in individual cases, for repeat prescriptions or cost approval applications)
Transmission channels – receipt of prescription data:
The transmission of prescription and patient data by prescribers and orthopaedic supply stores takes place via various technical channels. We expressly recommend the use of secure, encrypted transmission channels and provide a dedicated platform for this purpose:
Secure web form (recommended method): On our website we provide an encrypted web form through which prescriptions and patient data can be transmitted to us securely and end-to-end encrypted. This method meets current requirements for secure data transmission in the healthcare sector.
Other transmission channels: Where prescribers or orthopaedic supply stores transmit data via other channels (e.g. by post or via other channels within their area of responsibility), the data protection responsibility for the chosen transmission channel lies with the transmitting entity. We have no influence over the choice of transmission channel by third parties and process incoming data exclusively for the purpose of assistive device supply.
Post / personal handover: In individual cases, documents are also transmitted by post or in person at the time of device handover.
Direct contact by patients
In certain cases, patients contact us directly and transmit their data themselves. This may occur for various reasons:
Exercise of free choice of provider: Patients have the right to commission the assistive device supplier of their choice. They may therefore contact us independently and submit their prescription and personal data directly.
Self-paying patients (privately or publicly insured): Patients who bear all or part of the cost of care themselves – regardless of whether they are privately or publicly insured – frequently contact us directly to initiate and coordinate the care.
In these cases, the data you actively transmit will be used exclusively for carrying out the assistive device supply and – where applicable – for billing with your cost bearer.
Legal bases for direct contact:
- Art. 6(1)(b) GDPR (contract performance / pre-contractual measures at your request)
- Art. 9(2)(a) GDPR (explicit consent to the processing of your health data)
- Art. 9(2)(h) GDPR (healthcare)
6.2 Patient Data Processed
Master and contact data: First and last name, date of birth, home address, delivery address (where different), telephone number
Insurance and cost bearer data (for GKV patients): Health insurance fund, insurance number, insurance status, IK number of the cost bearer
Prescription and diagnosis data: Diagnosis (ICD code), medical prescription (prescription form), prescribed assistive device (aid number), name and contact details of the prescribing practice / clinic, BSNR and LANR of the prescriber, discharge documents from clinics
Care data: Planned care period (rental duration), device data (serial number, configuration), handover and return dates
Billing data: Approval numbers, cost commitments, delivery notes, prescription copies, invoice data
6.3 Care Process and Data Flow
Step 1 – Order receipt and care planning
We receive the prescription data from the medical practice, clinic or orthopaedic supply store and plan the assistive device supply on this basis. In individual cases, repeat prescriptions or cost commitments may also be received directly from the health insurance fund.
Step 2 – Cost clarification
For publicly insured patients (GKV):
Approval for cost coverage is obtained from the responsible health insurance fund or cost bearer – depending on the fund, via a communication platform specified by the cost bearer (electronic approval portals) or through the direct individual case approval process (in particular for smaller health insurance funds). Prescription and insurance data is transmitted to the cost bearer in this context. Care is only initiated after receipt of approval.
Should immediate care be medically urgent and the health insurance fund's approval still outstanding, we may begin care provisionally under the status "self-paying patient." After receipt of the GKV approval, a reimbursement claim is submitted to the health insurance fund. This requires your explicit written consent.
Legal basis: § 302 SGB V in conjunction with Art. 9(2)(h) GDPR, §§ 67 et seq. SGB X.
For self-paying patients (private patients and other self-paying patients):
The patient is presented with a rental agreement with cost coverage agreement for signature. Care is only initiated after verbal confirmation of cost coverage. By signing the rental agreement, generally at the time of delivery, the patient formally confirms the verbal consent previously given to the processing of their personal data in accordance with this Privacy Policy, as well as their explicit consent to the processing of their health data.
Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 9(2)(a) GDPR (explicit consent for health data).
Step 3 – Telephone care coordination
After approval by the health insurance fund or agreement on cost coverage by the self-paying patient, care is coordinated by telephone with the patient (delivery date, handover arrangements, instruction). Signature of the rental agreement (for self-paying patients) usually takes place at delivery.
Step 4 – Provision for patient supervisors
Data required for delivery and patient instruction is made available for retrieval by patient supervisors via a secure portal (see Section 6.4).
Step 5 – Care, instruction and return
Patient supervisors deliver the CPM device, instruct the patient in its use and collect the device after the expiry of the prescription period.
Step 6 – Billing
Billing with the statutory health insurance funds is carried out via the qualified data centre RZH (see Section 6.5). For self-paying patients, invoicing is carried out directly.
6.4 Patient Supervisors – Data Sharing and Role Clarification
Patient supervisors are independent service providers who are pre-qualified pursuant to § 126 SGB V. They carry out the direct patient care on site (delivery, device instruction, accompaniment during the care period, collection).
The patient data required for care (name, delivery address, telephone number, device and care data) is made available to patient supervisors via a secure portal – exclusively the information strictly necessary for the respective care provision.
As patient supervisors exercise independent decision-making powers as independent, pre-qualified service providers, they are to be classified under data protection law as independent controllers within the meaning of Art. 4(7) GDPR.
Legal basis: Art. 9(2)(h) GDPR in conjunction with § 22(1)(1)(b) BDSG; Art. 6(1)(b) GDPR.
Secure data exchange with patient supervisors
For the provision of care data to patient supervisors and for bidirectional communication during the care process, we use a secure communication platform of a German provider. Transmission is end-to-end encrypted: the content is technically not accessible to the platform operator. This ensures that:
- only authorised patient supervisors have access to the care data intended for them (identity verification)
- bidirectional communication is protected to the same standard
Patient supervisors are provided exclusively with the data strictly necessary for the respective care provision (principle of data minimisation, Art. 5(1)(c) GDPR).
Infrastructure provider: FTAPI Software GmbH, Feringastrasse 9, 85774 Unterföhring (Munich); hosting in Germany; no third-country transfer. An agreement for commissioned processing pursuant to Art. 28 GDPR exists with the provider, governing the processing of the infrastructure and any metadata. Due to end-to-end encryption, the provider has no access to the content of the transmitted care data.
Legal basis: Art. 9(2)(h) GDPR in conjunction with § 22(1)(1)(b) BDSG; Art. 6(1)(b) GDPR.
6.5 Systems and Service Providers Used in Patient Care
All patient data is processed exclusively in the following systems hosted in Germany:
Kumavision AG – Industry software (Microsoft Dynamics NAV / Navision)
- Purpose: Care planning, prescription management, billing GKV and self-paying patients
- Hosting: Microsoft Azure Germany
- Provider: Kumavision AG, Oberfischbach 3, 88677 Markdorf
- DPA pursuant to Art. 28 GDPR
M Assist GmbH – Consulting and support
- Purpose: Support and customisation of ERP processes
- Provider: M Assist GmbH, Camp-Spich-Str. 5, 53842 Troisdorf
- DPA pursuant to Art. 28 GDPR
H-SAS GmbH – Digital scanning solution for care documents
- Purpose: Digital capture of prescriptions, cost commitments and billing documents
- Hosting: Germany
- Provider: H-SAS GmbH, Camp-Spich-Str. 5, 53842 Troisdorf
- DPA pursuant to Art. 28 GDPR
FTAPI Software GmbH – Secure data transmission (inbound and outbound)
- Purpose (inbound): End-to-end encrypted receipt of prescriptions and patient data from prescribers and orthopaedic supply stores via the secure web form provided on our website
- Purpose (outbound): End-to-end encrypted provision of care data for patient supervisors via a secure communication platform; bidirectional communication
- Hosting: Germany
- Provider: FTAPI Software GmbH, Feringastrasse 9, 85774 Unterföhring (Munich)
- DPA pursuant to Art. 28 GDPR for infrastructure and metadata (in place)
- No third-country transfer
RZH – Data Centre for Healthcare Professions
- Purpose: Qualified billing with statutory health insurance funds pursuant to § 302 SGB V
- Hosting: Germany
- Provider: RZH Rechenzentrum für Heilberufe GmbH, Am Schornacker 32, 46485 Wesel
- DPA pursuant to Art. 28 GDPR
- No third-country transfer
In the context of billing via RZH, patient data (insurance data, prescription data, billing data) is transmitted to RZH, which passes it on to the respective health insurance funds on our behalf and in accordance with their instructions.
Legal basis: § 302 SGB V in conjunction with Art. 9(2)(h) GDPR.
No third-country transfer for patient data. All patient-related data remains in Germany.
6.6 Data Sharing in the Care Process – Overview
Recipient: Statutory health insurance funds (direct)
Purpose: Approval in individual case procedure
Legal Basis: § 302 SGB V, Art. 9(2)(h) GDPR, §§ 67 et seq. SGB X
Recipient: Communication platforms of the funds
Purpose: Electronic approval procedure
Legal Basis: § 302 SGB V, Art. 9(2)(h) GDPR
Recipient: RZH (data centre)
Purpose: Collective billing with health insurance funds
Legal Basis: § 302 SGB V, Art. 9(2)(h) GDPR; DPA Art. 28 GDPR
Recipient: Patient supervisors
Purpose: Delivery, instruction, collection
Legal Basis: Art. 9(2)(h) GDPR, Art. 6(1)(b) GDPR
Recipient: Prescribing doctors / clinics
Purpose: Follow-up queries on prescription, extensions
Legal Basis: Art. 9(2)(h) GDPR, Art. 6(1)(b) GDPR
Recipient: FTAPI Software GmbH
Purpose: Provision of secure transmission infrastructure (inbound: prescribers / orthopaedic supply stores; outbound: patient supervisors); no knowledge of content due to end-to-end encryption
Legal Basis: DPA Art. 28 GDPR (for infrastructure / metadata)
Recipient: Lawyers / public authorities
Purpose: In individual cases where legally necessary
Legal Basis: Art. 6(1)(c) GDPR
Recipient: Kumavision AG / M Assist GmbH
Purpose: System hosting and operation
Legal Basis: DPA Art. 28 GDPR
Recipient: H-SAS GmbH
Purpose: Digital document capture
Legal Basis: DPA Art. 28 GDPR
6.7 Legal Bases Patient Care – Summary
Processing Operation: Care planning based on prescription
Legal Basis: Art. 9(2)(h) and (i) GDPR in conjunction with § 22(1)(1)(b) BDSG
Processing Operation: Cost clarification with GKV
Legal Basis: Art. 9(2)(h) GDPR; § 302 SGB V; §§ 67 et seq. SGB X
Processing Operation: Rental agreement with self-paying patients
Legal Basis: Art. 6(1)(b) GDPR; Art. 9(2)(a) GDPR
Processing Operation: Telephone care coordination
Legal Basis: Art. 6(1)(b) GDPR
Processing Operation: Provision for patient supervisors
Legal Basis: Art. 9(2)(h) GDPR; Art. 6(1)(b) GDPR
Processing Operation: Direct transmission / direct contact by patients
Legal Basis: Art. 6(1)(b) GDPR; Art. 9(2)(a) and (h) GDPR
Processing Operation: Billing via RZH
Legal Basis: Art. 6(1)(c) GDPR; § 302 SGB V
Processing Operation: MDR documentation / vigilance
Legal Basis: Art. 6(1)(c) GDPR (MDR, MPDG)
6.8 Retention Periods – Patient Care
Type of data: Tax and commercial law documents
Retention period: 10 years
Legal Basis: § 147 AO, § 257 HGB
Type of data: Medical device documentation
Retention period: at least 10 years after placing on the market
Legal Basis: MDR (EU 2017/745), MPDG
Type of data: GKV billing documents
Retention period: in accordance with health insurance fund requirements
Legal Basis: § 302 SGB V
Type of data: Social data
Retention period: in accordance with § 84 SGB X
Legal Basis: § 84 SGB X
Type of data: General care correspondence
Retention period: 6 years
Legal Basis: § 257 HGB
6.9 Social Data pursuant to SGB X
Where we process data in the context of fund-based care that originates from or is transmitted to a statutory cost bearer (health insurance fund), this constitutes social data within the meaning of § 67(2) SGB X. This is subject to the special social data protection provisions of §§ 67 et seq. SGB X. We process this data exclusively within the scope of the legally permissible purposes of assistive device supply and billing.
6.10 Online Status Query – Prescription and Approval Status
Applicable to: www.enovis-medtech.de
On our website, patients can retrieve the current processing status of their CPM care online – in particular the status of the approval procedure with the statutory health insurance fund.
How it works: By entering the 10-digit insurance number, the current prescription and approval status can be viewed.
Data processed:
- Insurance number (10 digits)
- Query time (server log)
- IP address (technical, pursuant to Section 4.1)
- Displayed status information (prescription status, health insurance fund approval status)
Purpose: Informing the patient about the progress of the approval procedure with the statutory health insurance fund; transparency regarding the care process.
System: The status query is made against the care systems described in Section 6.5 (Kumavision). Only data that is already being processed as part of the ongoing care is displayed.
Hosting: Germany (pursuant to Section 6.5).
Retention period: The query itself is not stored; the underlying care data is retained in accordance with Section 6.8.
Legal basis:
- Art. 9(2)(h) GDPR in conjunction with § 22(1)(1)(b) BDSG (healthcare)
- Art. 6(1)(b) GDPR (contract performance / pre-contractual measures)
Data security note: The status query is SSL/TLS encrypted (see Section 4.2). The status query requires only the patient's insurance number. We recommend carrying out the status query only on private, secured devices.
Note for privately insured patients: Privately insured patients are contacted directly by their patient supervisor as soon as the prescription has been received by us. An online status query is not provided for this group.
7. Customer Portal (enovis-kundenportal.de)
Applicable to: https://enovis-kundenportal.de/de
7.1 Description and Purpose
The customer portal is the central communication and service offering for commercial customers in the DACH region. It comprises the following functional areas:
Area: Ordering
Functions included: Order by e-mail, EDI requests/information, General Terms and Conditions (T&Cs); webshop access (in preparation)
Area: Shipment information
Functions included: Shipment tracking of goods deliveries
Area: After-sales service
Functions included: Product complaints, product returns, repair requests, service & maintenance requests
Area: Accounting
Functions included: Invoice duplicates, invoice corrections, invoice delivery by e-mail
Area: Contact
Functions included: Field service map, service hotlines, contact requests, customer feedback
Area: Downloads
Functions included: Product information, documents, forms
Requests are recorded as tickets in the backend and forwarded to the responsible internal teams. An interface to Salesforce (SFDC) enables direct ticket creation by field service employees.
7.2 Operator and Hosting: BELPOLTEX B.V.
The customer portal is technically operated and hosted by BELPOLTEX B.V.
Provider: Belpoltex B.V., Grimbergsteenweg 105/4, 1853 Grimbergen, Belgium (represented by Maxime Witters).
Purpose: Provision of the customer portal; hosting of frontend and backend ticketing system; system and software maintenance; data storage and processing.
Hosting: European Union (EU) – no transfer of personal data to third countries.
Safeguards: DPA pursuant to Art. 28 GDPR.
7.3 Data Processed in the Customer Portal
- Company and customer data (company name, customer number)
- Personal data of contact persons (first and last name, function)
- Contact data (e-mail address, telephone number)
- Address and delivery data (billing address, delivery address where different)
- Order-related data (article number, serial number, error description, complaint reason, invoice number, product photos where applicable for complaints)
- Usage and connection data (IP address, page views, click behaviour, session duration, device information, source)
7.4 Legal Bases
- Art. 6(1)(b) GDPR (contract performance / processing of service requests)
- Art. 6(1)(c) GDPR (legal obligations, in particular MDR / MPDG for complaints)
- Art. 6(1)(f) GDPR (legitimate interest in efficient customer communication)
7.5 Salesforce – CRM, Sales and Marketing
We use Salesforce as the central system for customer relationship management, sales management and marketing communication.
Provider: Salesforce.com, Inc., Salesforce Tower, 415 Mission Street, San Francisco, CA 94105, USA.
Hosting: USA.
Safeguards: DPF certification (EU-US Data Privacy Framework); SCC pursuant to Art. 46 GDPR; DPA pursuant to Art. 28 GDPR. See Section 1.4.
Note: Only professional contact data is processed in Salesforce. Patient data, health data and prescription data are not processed in Salesforce at any time and remain exclusively in the German systems Kumavision and H-SAS (see Section 6.5).
7.5.1 Affected Groups of Persons
In Salesforce, we process professional contact and communication data of the following groups:
Commercial customers and business partners (B2B): Orthopaedic supply stores, clinics, purchasing associations and other business partners with whom a contractual or business relationship exists.
Prescribers and medical professionals: General practitioners, specialists and hospital doctors who prescribe or recommend products from our range. This covers all product categories of our company – from assistive devices on medical prescription to products recommended in the context of medical consultation (e.g. IGeL products). These persons have no direct contractual relationship with us; their professional contact data is processed exclusively in connection with maintaining professional relationships in the context of our business activities.
Emergency depot managers (medical practices and clinics): Medical practices, clinics and other medical facilities at which we provide assistive devices for immediate emergency care within the framework of a depot agreement. A contractual agreement (depot or consignment contract) exists with these facilities. The data processed in this context relates exclusively to the contact persons responsible for depot management at the respective facility, as well as depot and delivery-related data. Patient data is not processed in the context of emergency depot management.
7.5.2 Sales Cloud – CRM and Sales Management
Purpose:
- Management of business contacts and customer relationships (B2B customers)
- Maintenance of prescriber and specialist contacts for field service support and professional communication across all product categories
- Management of emergency depot agreements: contact maintenance, stock monitoring, delivery planning and billing
- Synchronisation of complaint and service data from the customer portal
- Direct ticket creation by field service employees
- Documentation of sales and communication processes
Data processed:
- Professional contact data: first and last name, function / speciality, practice or company name, address, business e-mail address, telephone number
- Communication and visit history (field service)
- Depot-related data: depot location, stock data, delivery history, device data (serial numbers, product categories)
- Complaint and service data (for B2B customers)
- Sales-related transaction history
Retention period: For as long as the business, prescriber or depot relationship is active; in the absence of contact or upon termination of the relationship, 2 years, unless statutory retention obligations apply.
Legal bases:
- Art. 6(1)(b) GDPR – contract performance for B2B customers, business partners and emergency depot contractual partners
- Art. 6(1)(f) GDPR – legitimate interest in maintaining professional relationships with prescribers and medical professionals within the scope of our activities as a medical device provider, and in efficient sales management
7.5.3 Marketing Cloud Engagement – B2B Professional Communication
Purpose:
- Sending professional e-mail communications to B2B customers, prescribers, medical professionals and depot managers (e.g. product information, care guidance, specialist information on new products, depot-relevant service updates)
- Management of communication preferences and objections (opt-out)
- Segmentation of target groups for targeted professional communication
Data processed:
- Business e-mail address, name, function / speciality, company / practice / facility
- Communication history (dispatch status, aggregated open and click behaviour)
- Opt-out status and objection documentation
Legal bases:
- Art. 6(1)(b) GDPR – contract performance for contractually bound depot partners (where communication serves the purpose of contract processing)
- Art. 6(1)(f) GDPR (legitimate interest) for professional communication with:
- B2B customers, where an ongoing or concluded business relationship exists (§ 7(3) UWG)
- Prescribers and medical professionals, where communication has a direct professional connection to our products and services, the recipient is addressed in a professional capacity and no objection has been lodged
- Art. 6(1)(a) GDPR (consent) for recipients who have expressly consented to receiving communications
Right to object / opt-out: You may object to the processing of your data for communication purposes at any time – via the unsubscribe link in each e-mail or by contacting our Data Protection Officer (see Section 1.3). Objections are implemented immediately and documented permanently.
Retention period: Active contact data for as long as the relationship exists, thereafter or in the absence of contact 2 years; opt-out documentation beyond this permanently to ensure the effect of the objection.
E-mail sending service – Maileon: We carry out the technical e-mail dispatch as well as the management and permanent documentation of opt-outs and objections via Maileon.
Provider: XQueue GmbH, Mainzer Landstrasse 68, 60325 Frankfurt am Main
Hosting: Germany
Data processed: Business e-mail address, name (where included in dispatch), dispatch status, delivery confirmations, bounce information, opt-out status and timestamp
Safeguards: DPA pursuant to Art. 28 GDPR (in place); no third-country transfer
Retention period: Dispatch data (delivery status, bounce information): 6 months after dispatch; opt-out documentation: permanently to ensure the effect of the objection.
7.6 Product Complaints and MDR Reporting Obligations
Data from product complaints is also processed to fulfil our reporting obligations under MDR (EU 2017/745) and MPDG and may necessitate a report to the BfArM (Federal Institute for Pharmaceuticals and Medical Devices).
Legal basis: Art. 6(1)(c) GDPR.
7.7 Retention Periods – Customer Portal
Type of data: Complaint / repair documentation (MDR)
Retention period: At least 10 years after placing on the market
Type of data: Commercial / tax law documents
Retention period: 10 years (§ 147 AO, § 257 HGB)
Type of data: General service communication
Retention period: 6 years (§ 257 HGB)
Type of data: Usage and connection data
Retention period: In accordance with BELPOLTEX retention policies; maximum 30 days
8. Oracle EBS – B2B Order Processing
Applicable to: B2B order processing (internal)
For the commercial processing of B2B orders, we use Oracle E-Business Suite (Oracle EBS) as a group-wide SaaS solution of the Enovis Group.
Provider: Oracle Corporation (via Enovis Group framework agreement).
Purpose: ERP-supported order processing, delivery and invoice management in the B2B area.
Data processed: Company and contact data of business partners, order, delivery and invoice data, product master data.
Patient data, health data and prescription data are not processed in Oracle EBS and remain exclusively in the German systems Kumavision and H-SAS.
Hosting: USA.
Safeguards: SCC pursuant to Art. 46(2)(c) GDPR; DPA pursuant to Art. 28 GDPR (via Enovis Group framework agreement). Note: Oracle EBS does not have its own DPF certification; safeguarding is provided exclusively via SCC and DPA. See Section 1.4.
Legal basis: Art. 6(1)(b) GDPR (contract performance / B2B order processing); Art. 6(1)(f) GDPR (legitimate interest in efficient order processing).
9. Cookies, Tracking and Consent Management
Applicable to: www.enovis-medtech.de and https://enovis-kundenportal.de/de
9.1 Principle: Consent before Tracking
Our websites use cookies and comparable tracking technologies. Pursuant to § 25(1) TDDDG, the storing of information on the end device is generally only permissible with prior active consent. The sole exception is technically strictly necessary cookies.
We use the certified consent management platform Usercentrics (see Section 9.2), which is displayed on the first visit to each of our websites – before non-necessary cookies are set – and awaits your decision.
9.2 Consent Management – Usercentrics
Applicable to: www.enovis-medtech.de and https://enovis-kundenportal.de/de
To obtain, document and manage your cookie consents, we use the consent management platform Usercentrics.
Provider: Usercentrics GmbH, Sendlinger Strasse 7, 80331 Munich, Germany.
Purpose: Obtaining and documenting consents pursuant to § 25 TDDDG and Art. 7 GDPR; management and proof of consents given and withdrawn; provision of the cookie banner.
Data processed: IP address (truncated), consent timestamp, consent status per cookie category, browser and device information, consent ID.
Hosting: Germany / EU
Retention period: Consent records 3 years (proof obligation Art. 7(1) GDPR)
Safeguards: DPA pursuant to Art. 28 GDPR; no third-country transfer
Legal basis: § 25(2) No. 2 TDDDG (consent cookie technically necessary); Art. 6(1)(c) GDPR (proof obligation Art. 7 GDPR); Art. 6(1)(f) GDPR (legitimate interest in legally compliant consent management)
9.3 Requirements for Consent
- Opt-in: Only active consent qualifies as consent; no "continued browsing as consent"
- Equal ease: Declining is equally easy as accepting
- Informed: Purpose, duration and third-party recipients are communicated in the banner
- No nudging: No subliminal influence towards consent
- Withdrawal: At any time via the cookie settings in the website footer
- Compliance with the prohibition of coupling: Consent not linked to use of the website
9.4 Cookie Categories
Cookie type: Technically necessary
Description: Session management, login status, language settings
Consent required: No
Legal Basis: Art. 6(1)(f) GDPR
Cookie type: Analytics (GA4)
Description: Usage statistics, behaviour analysis, conversion tracking
Consent required: Yes
Legal Basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG
Cookie type: Marketing
Description: Retargeting, personalised advertising (Google Ads)
Consent required: Yes
Legal Basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG
9.5 Google Analytics 4 (GA4)
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Analysis of user behaviour, campaign measurement (SEA, SEO, newsletter, social media), landing page performance, BigQuery export / Power BI reporting (DACH).
Data processed: IP address (anonymised), user agent, page views, scroll depth, click and navigation behaviour, session duration, pseudonymised Google user ID / device ID, campaign data, coarse location information.
Technical safeguards: IP anonymisation activated; Google Consent Mode v2 implemented; GA4 loads exclusively after consent has been given; data retention period set to 2 months; reset of deletion cycle deactivated; no data sharing for Google services; no access for Account Specialists / benchmarking; no data enrichment; no user ID; no regional device data.
Google Signals / Google Ads: Activated only on the basis of marketing consent.
Hosting: EU / USA.
Safeguards: DPF certification; DPA pursuant to Art. 28 GDPR; DPIA carried out. See Section 1.4.
Legal bases: § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR (consent); third-country transfer on the basis of DPF certification (Art. 45 in conjunction with Art. 46 GDPR). See Section 1.4.
Withdrawal / opt-out: Withdrawable at any time via cookie settings (footer); additionally the browser plugin can be used: https://tools.google.com/dlpage/gaoptout; further information: https://policies.google.com/privacy
10. Newsletter
Applicable to: www.enovis-medtech.de
If you wish to receive the newsletter offered on our website, we require your e-mail address and confirmation of your consent (double opt-in procedure).
Data processed: E-mail address, name where applicable; confirmation record of consent.
Purpose: Dispatch of the newsletter to recipients who have consented to its receipt.
Retention period: Until cancellation of the newsletter subscription.
Legal basis: Art. 6(1)(a) GDPR (consent).
Withdrawal: At any time via the "unsubscribe" link in the newsletter. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.
11. Links to Social Media Platforms
Applicable to: www.enovis-medtech.de and https://enovis-kundenportal.de/de
Our websites contain icons in the footer with links to the following social media platforms:
- YouTube (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA)
- Facebook / Instagram (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland)
- LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland)
- Xing (New Work SE, Am Strandkai 1, 20457 Hamburg, Germany)
These icons are exclusively external hyperlinks. When you access our website, no data is transmitted to these platforms. Data processing by the respective platform only takes place when you actively click on the link and access the external platform. From that point on, the privacy policy of the respective platform applies – not this Privacy Policy.
We have no influence over the data processing by these platforms and recommend reading the respective privacy notices before using the platforms.
12. Overview of All Systems and Service Providers Used
This table provides a quick overview of all systems and service providers described in this Privacy Policy. For detailed information on individual systems, see the relevant sections:
Patient care: Section 6.5
B2B order processing: Section 8
Customer portal: Sections 7.2 and 7.5
Website operation: Sections 4.3, 5.2, 5.3, 9.2, 9.5, 11
Customer portal operation: Sections 4.4, 7.2, 9.2
Employees & applicants: Sections 13.3 and 14.2
Telephony & call centre: Section 13.3.5
Third-country transfers: See Section 1.4 for safeguarding mechanisms. All processors have concluded a data processing agreement (DPA) pursuant to Art. 28 GDPR.
System / Service Provider: Kumavision AG
Scope: Patient care (Sections 6.5, 6.10)
Purpose: Care, GKV / private billing, online status query
Hosting: Germany (Azure DE)
Safeguards: DPA Art. 28 GDPR
System / Service Provider: M Assist GmbH
Scope: Patient care (Section 6.5)
Purpose: Support / customisation Kumavision
Hosting: Germany
Safeguards: DPA Art. 28 GDPR
System / Service Provider: H-SAS GmbH
Scope: Patient care (Section 6.5)
Purpose: Digital document capture
Hosting: Germany
Safeguards: DPA Art. 28 GDPR
System / Service Provider: FTAPI Software GmbH
Scope: Patient care (Sections 6.1, 6.4, 6.5)
Purpose: Secure data transmission inbound (prescribers / orthopaedic supply stores) and outbound (patient supervisors); end-to-end encryption
Hosting: Germany
Safeguards: DPA Art. 28 GDPR; no third-country transfer
System / Service Provider: RZH (data centre)
Scope: Patient care (Section 6.5)
Purpose: GKV billing § 302 SGB V
Hosting: Germany
Safeguards: DPA Art. 28 GDPR
System / Service Provider: Vercel Inc.
Scope: Website operation (Section 4.3) – www.enovis-medtech.de
Purpose: Web hosting main website
Hosting: USA (global CDN)
Safeguards: DPF + SCC + DPA Art. 28 GDPR
System / Service Provider: BELPOLTEX B.V
Scope: Customer portal (Section 7.2)
Purpose: Hosting & operation portal + ticketing system
Hosting: EU (Belgium)
Safeguards: DPA Art. 28 GDPR
System / Service Provider: Usercentrics GmbH
Scope: Main website (Section 9.2); Customer portal (Section 9.2)
Purpose: Cookie consent management (CMP)
Hosting: Germany
Safeguards: DPA Art. 28 GDPR; no third-country transfer
System / Service Provider: Salesforce Sales Cloud
Scope: CRM / sales / emergency depots (Section 7.5.2)
Purpose: CRM, contact maintenance B2B customers, prescribers, medical staff and depot managers
Hosting: USA
Safeguards: DPF + SCC + DPA Art. 28 GDPR
System / Service Provider: Salesforce Marketing Cloud Engagement
Scope: B2B professional communication (Section 7.5.3)
Purpose: E-mail professional communication, opt-out management
Hosting: USA
Safeguards: DPF + SCC + DPA Art. 28 GDPR
System / Service Provider: Maileon (XQueue GmbH)
Scope: B2B professional communication (Section 7.5.3)
Purpose: E-mail dispatch, opt-out documentation
Hosting: Germany
Safeguards:DPA Art. 28 GDPR; no third-country transfer
System / Service Provider: Cloudflare, Inc.
Scope: Customer portal (Section 4.4)
Purpose: WAF, bot detection, DDoS protection
Hosting: USA (EU PoPs)
Safeguards: DPF + SCC + DPA Art. 28 GDPR
System / Service Provider: Google Analytics 4
Scope: Both websites (Section 9.5)
Purpose: Web analytics, marketing campaign measurement
Hosting: EU / USA
Safeguards: Consent + DPF + DPA Art. 28 GDPR
System / Service Provider: Google reCAPTCHA
Scope: Main website (Section 5.2)
Purpose: Bot protection for forms
Hosting: USA
Safeguards: Consent + DPF + DPA Art. 28 GDPR
System / Service Provider: Lime Connect (Userlike)
Scope: Main website (Section 5.3)
Purpose: Chat widget, live chat, contact
Hosting: Germany
Safeguards: DPA Art. 28 GDPR; no third-country transfer
System / Service Provider: Workday, Inc.
Scope: Employees & applicants (Sections 13.3.1, 14.2)
Purpose: HR management, recruiting
Hosting: USA
Safeguards: DPF + SCC + DPA Art. 28 GDPR
System / Service Provider: DATEV eG
Scope: Employees (Section 13.3.2)
Purpose: Payroll accounting
Hosting: Germany
Safeguards: DPA Art. 28 GDPR
System / Service Provider: GFOS mbH
Scope: Employees (Section 13.3.3)
Purpose: Time recording, absence management
Hosting: Germany
Safeguards: DPA Art. 28 GDPR
System / Service Provider: AON
Scope: Employees (Section 13.3.4)
Purpose: Occupational pension, insurance management
Hosting: Germany
Safeguards: DPA Art. 28 GDPR
System / Service Provider: RingCentral Germany GmbH
Scope: Telephony – employees & customers (Section 13.3.5)
Purpose: Company-wide voice communication SIP telephony
Hosting: Germany (EU)
Safeguards: DPA Art. 28 GDPR; DPF (parent company RingCentral, Inc.)
System / Service Provider: RingCentral France SAS / NICE
Scope: Call centre – employees & customers (Section 13.3.5)
Purpose: Intelligent call distribution, IVR, service management
Hosting: France (EU)
Safeguards: DPA Art. 28 GDPR; adequacy decision Israel Art. 45 GDPR (NICE Ltd.)
System / Service Provider: Microsoft 365
Scope: Employees & B2B partners (Section 13.3.6)
Purpose: Productivity and communication platform
Hosting: EU (EU Data Boundary)
Safeguards: DPF + SCC + DPA Art. 28 GDPR
13. Data Protection for Employees
Applicable to: all current employees
13.1 Purpose and Legal Bases
We process personal data of our employees for the purpose of establishing, performing and terminating the employment relationship and for fulfilling legal obligations.
Legal bases:
- § 26 BDSG in conjunction with Art. 88 GDPR (employee data protection)
- Art. 6(1)(b) GDPR (performance of the employment contract)
- Art. 6(1)(c) GDPR (legal obligations: tax, social security, employment law)
- Art. 6(1)(f) GDPR (legitimate interest: IT security, company organisation)
- Art. 6(1)(a) GDPR (consent for voluntarily provided additional data)
13.2 Categories of Data Processed
Mandatory stored data:
Data category: Master data
Examples: First and last name, date of birth, place of residence
Data category: Contact data
Examples: Private telephone number, e-mail address where applicable
Data category: Contract data
Examples: Start date, function / position, remuneration, working hours, fixed-term status
Data category: Organisational data
Examples: Cost centre, line manager, location, department
Data category: Tax / social security data
Examples: Tax class, tax ID, social security number, health insurance fund
Data category: Bank data
Examples: Bank account details for salary payment
Voluntarily providable data (career planning in Workday): Employees may additionally store voluntary further information (qualification certificates, language skills, competencies, career goals, mentoring preferences, other profile information).
Important note: Voluntary information is provided on the basis of your consent (Art. 6(1)(a) GDPR). No disadvantages arise for the employment relationship from not providing such information. Information on special categories of personal data (Art. 9 GDPR) requires explicit consent, which is obtained separately.
13.3 Systems Used
13.3.1 Workday – HR Information System
In Workday, employee appraisals, performance reviews (including 360° feedback), career planning and target agreements as well as master and contract data management are digitally supported. Access is role-based and restricted to what is required.
Provider: Workday, Inc., 6110 Stoneridge Mall Road, Pleasanton, CA 94588, USA.
Data processed: Master data, contact data, contract data, organisational data, tax / social security data, bank data, voluntarily provided additional data (qualifications, competencies, career goals).
Purpose: Personnel management, performance appraisal, career planning, contract performance.
Hosting: USA.
Safeguards: DPF certification; SCC pursuant to Art. 46 GDPR; DPA pursuant to Art. 28 GDPR. See Section 1.4.
Retention period: During the employment relationship and beyond in accordance with statutory retention obligations.
Legal basis:
- Art. 6(1)(b) GDPR (contract performance)
- Art. 6(1)(a) GDPR (consent for voluntary additional data)
- Art. 6(1)(c) GDPR (legal obligations: tax, social security law)
13.3.2 Payroll and Financial Accounting (DATEV)
Provider: DATEV eG, Paumgartnerstrasse 6–14, 90429 Nürnberg.
Data processed: Master data, tax ID, social security number, salary data, bank account details
Purpose: Preparation and processing of payroll accounting, fulfilment of tax and social security obligations
Hosting: Germany and EU
Safeguards: DPA pursuant to Art. 28 GDPR; no third-country transfer.
Retention period: 10 years (pursuant to § 147 AO, § 257 HGB)
Legal basis:
- Art. 6(1)(b) and (c) GDPR
- § 26(1) BDSG
13.3.3 Time Recording and Absence Management (GFOS)
Provider: GFOS mbH, Cathostrasse 5, 45356 Essen.
Data processed: Name, date of birth, department, working hours, holiday data, absence data
Purpose: Recording of working hours, management of absences (holiday, illness), personnel management
Hosting: Germany
Safeguards: DPA pursuant to Art. 28 GDPR; no third-country transfer.
Retention period: 10 years (pursuant to § 147 AO, § 257 HGB)
Legal basis:
- Art. 6(1)(b) and (c) GDPR
- § 16(2) ArbZG (working time recording obligation)
- § 26(1) BDSG
13.3.4 Occupational Pension and Insurance Management (AON)
Provider: AON (contractual partner pursuant to Enovis Group framework agreement).
Data processed:
- Personal master data (name, date of birth, address)
- Service period data (start, end, career)
- Salary and pension data
- Bank account details
- Health data where applicable for insurance application (with explicit consent)
Persons affected: Employees, pensioners, former employees, surviving dependants (widows/orphans), persons entitled to pension equalisation
Purpose: Management of insurance policies and occupational pension; processing of insurance applications; pension management and claims processing
Hosting: Germany
Retention period: During the insurance relationship; 10 years after termination for archiving purposes.
Legal basis:
- Art. 6(1)(b) and (c) GDPR
- Art. 9(2)(a) GDPR (explicit consent for health data)
- § 26(1) BDSG
13.3.5 Telephony and Call Centre Software – RingCentral & NICE
Applicable to: all employees and customers who contact us by telephone
For our corporate communication and telephone customer service, we use two integrated systems:
- RingCentral – as the group-wide telephone system with SIP telephony
- NICE – as call centre software for intelligent call distribution and service management
Both systems are integrated via a group-wide framework agreement (Master Services Agreement) between RingCentral, Inc. and the Enovis Group parent company.
13.3.5.1 RingCentral – Telephone System
Provider (operational): RingCentral Germany GmbH, Caffamacherreihe 7, 20355 Hamburg, Germany
Parent company: RingCentral, Inc., 20 Davis Drive, Belmont, CA 94002, USA
Data processed:
- Telephone numbers (internal and external)
- Connection data (time, duration, call direction)
- Device IDs and network data (for QoS monitoring)
Purpose:
- Provision of company-wide voice communication (internal and external)
- Availability for customers, partners and service providers
- Technical quality monitoring of connection quality (QoS reporting)
- Seamless device switching during active calls (call flip)
Functions not used: AI-based call evaluation, Agent Assist, virtual assistants, CRM integration, Microsoft Teams integration, call recording.
Hosting: Germany (EU)
Safeguards: DPA pursuant to Art. 28 GDPR with RingCentral Germany GmbH; RingCentral, Inc. is DPF-certified. Operational contractual partner is a German company in the EEA.
Retention period: Connection data for a maximum of 6 months, unless a statutory obligation to retain for longer applies.
Legal basis:
- Art. 6(1)(b) GDPR (contract performance / communication with customers and partners)
- Art. 6(1)(f) GDPR (legitimate interest in functional and secure corporate communication)
13.3.5.2 NICE – Call Centre Software
Provider (operational): RingCentral France SAS, 6 Cité de Londres, 75009 Paris, France
Software manufacturer: NICE Ltd., 13 Zarchin Street, Ra'anana, Israel
Data processed:
- Telephone numbers and connection data of callers
- Call details: time, duration, routing information, waiting time
- Department selection (Interactive Voice Response (IVR) inputs)
- Aggregated, anonymised performance metrics of employees (KPIs)
Purpose:
- Intelligent distribution of incoming calls to available employees (ACD / routing)
- Pre-qualification of calls via interactive voice response (IVR)
- Management of queues and time-based forwarding
- Measurement of service quality through aggregated, anonymised metrics
Functions not used: Call recording, voice analysis, sentiment analysis, omnichannel functions (chat, e-mail, social media), real-time adherence (individual employee monitoring), scorecards, AI-based content analysis. There is no monitoring function for supervisors and no room surveillance function.
Hosting: France (EU)
Safeguards: DPA pursuant to Art. 28 GDPR with RingCentral France SAS; NICE Ltd. (Israel) is subject to the EU adequacy decision pursuant to Art. 45 GDPR.
Retention period: Connection and routing data maximum 30 days; aggregated metrics are anonymised and are not subject to a personal retention period.
Legal basis:
- Art. 6(1)(b) GDPR (contract performance / processing of customer enquiries)
- Art. 6(1)(f) GDPR (legitimate interest in efficient availability and service quality)
Data protection for employees: All performance data is collected exclusively in aggregated and anonymised form. Individual performance monitoring of individual employees does not take place. Processing is carried out in accordance with § 26 BDSG and any existing works agreements.
13.3.6 Microsoft 365 – Productivity and Communication Platform
Applicable to: all employees and, in the B2B context, external interlocutors
We use Microsoft 365 (M365) as the group-wide productivity and communication platform. Licensing is via a group-wide framework agreement of the Enovis Group. Among the services used are:
- Communication: Outlook (e-mail), Microsoft Teams (video conferences, chat, telephony)
- Productivity: Word, Excel, PowerPoint, OneNote
- Collaboration: SharePoint, Teams channels, Loop, Planner
- AI support: Microsoft Copilot (where licensed and activated)
Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Parent company: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA
Data processed:
Category: Communication data
Examples: E-mail addresses, message content, call metadata
Category: Connection data
Examples: Time, duration, participants of meetings and calls
Category: Content data
Examples: Documents, tables, presentations, notes, planning entries
Category: Usage data
Examples: Login times, applications used, activity logs
Category: Teams recordings
Examples: Recordings of meetings (where activated and all participants informed)
Category: Copilot data
Examples: Inputs and outputs when using AI functions (where activated)
Purpose:
- Internal and external corporate communication (e-mail, chat, video conference)
- Creation, editing and joint use of work documents
- Project planning and task management
- Conducting meetings and training sessions (internal and with B2B partners)
- Support of work processes through AI functions (Microsoft Copilot, where activated)
Hosting: Microsoft EU Data Boundary – data is stored and processed exclusively in European data centres (EU / EEA).
Safeguards: DPA pursuant to Art. 28 GDPR (Microsoft Data Protection Addendum); SCC pursuant to Art. 46 GDPR for any transfers to the US parent company; DPF certification; group-wide framework agreement with activated EU Privacy Settings.
Retention period: Duration of the employment relationship or business relationship; after termination, data is deleted in accordance with the configured retention policies, at the latest however after expiry of the legally required retention periods (maximum 10 years for tax and commercial law relevant content).
Legal bases:
- Art. 6(1)(b) GDPR – performance of the employment contract (for employees)
- Art. 6(1)(f) GDPR – legitimate interest in efficient and secure corporate communication
- Art. 6(1)(f) GDPR – legitimate interest in communication with external B2B contacts within existing business relationships
- § 26 BDSG in conjunction with Art. 88 GDPR – employee data protection
- Art. 6(1)(a) GDPR – consent for optional functions such as meeting recordings
Special notes:
Meeting recordings: Meetings in Microsoft Teams may be recorded at the instigation of the inviting employee. A recording takes place exclusively with the explicit consent of all participants at the beginning of the meeting. The recording remains in the area of responsibility of the inviting employee and is managed by them. No central retention period is set; the recording is to be deleted once the purpose has ceased.
Legal basis: Art. 6(1)(a) GDPR (consent).
Microsoft Copilot (AI functions): Where Microsoft Copilot is activated, inputs and context data are used for AI-supported processing. Microsoft processes this data exclusively for the provision of the service and not for training AI models (pursuant to the Microsoft Data Protection Addendum). Processing takes place within the EU Data Boundary.
External communication via Teams (B2B): Microsoft Teams is also used for communication with external B2B partners (customers, suppliers). Connection and communication data of external participants is processed in this context. External participants are informed about data processing at the beginning of a meeting.
No processing of patient data: Patient data, health data and prescription data are not processed via Microsoft 365 at any time and remain exclusively in the German systems Kumavision and H-SAS (see Section 6.5).
13.4 Data Sharing
13.4.1 Intra-Group Data Sharing
We are part of the Enovis Group. Employee data may be shared with other Enovis Group companies in the context of intra-group processes, in particular for organisational structure, personnel management and corporate talent development.
Safeguards: SCC pursuant to Art. 46(2)(c) GDPR; works agreements pursuant to Art. 88 GDPR in conjunction with § 26 BDSG.
Legal basis: Art. 6(1)(b) and (c) GDPR.
13.4.2 Sharing with External Processors
To fulfil our personnel administration, payroll, time management and insurance tasks, we work with specialised external processors (see Section 13.3). These process employee data only on our instructions and in compliance with strict data protection requirements pursuant to Art. 28 GDPR. Where data is transferred to third countries in this context (in particular Workday, USA – Section 13.3.1), this is done on the basis of the safeguarding mechanisms described in Section 1.4 (DPF, SCC, DPA).
13.4.3 Sharing with External Recipients Who Are Not Processors
In addition, we share employee data with the following external entities, which do not act as processors but as independent controllers within the meaning of Art. 4(7) GDPR:
Germany:
- Tax authorities (tax office) – for payroll tax notifications
- Social security providers and health insurance funds – for social security notifications
- Trade association (Berufsgenossenschaft) – for accident insurance notifications
- Benefit providers (pension insurance, employment agency where applicable) – for benefit processing
Legal basis: Art. 6(1)(c) GDPR (legal obligations pursuant to EStG, SGB IV, SGB X, ArbZG)
Austria:
For employees whose place of employment is in Austria, we engage a tax advisory firm or payroll office for the preparation of payroll accounts and the fulfilment of the associated tax and social security reporting obligations.
The engaged party acts in the exercise of its professional and legal obligations as an independent controller within the meaning of Art. 4(7) GDPR. It is subject to the Austrian Act on Tax Advisers (WTBG 2017) and the relevant data protection obligations, and processes the transmitted data exclusively within the scope of the legally provided purposes.
Data categories transmitted:
- Master data (name, date of birth, address)
- Tax data (tax class, tax ID / social security number)
- Salary data, bank account details
- Absence and working time data (where required for payroll)
Recipients of notifications (via the tax advisory office):
- Austrian tax office (FinanzOnline) – for payroll tax notifications
- Austrian social security providers (ÖGK, AUVA, PVA) – for social security notifications
- Competent authorities under the Corporate Employee and Self-Employed Persons Provision Act (BMSVG) – for severance contributions
Legal basis: Art. 6(1)(c) GDPR in conjunction with the relevant Austrian legal provisions, in particular:
- Federal Fiscal Code (Bundesabgabenordnung / BAO)
- General Social Insurance Act (Allgemeines Sozialversicherungsgesetz / ASVG)
- Income Tax Act (Einkommensteuergesetz / EStG) in conjunction with payroll tax guidelines
- Corporate Employee and Self-Employed Persons Provision Act (BMSVG)
13.5 Retention Periods – Employee Data
The retention period for employee data depends on the purpose of the processing and applicable laws:
Type of data: Payroll documents
Retention period: 10 years
Legal Basis: § 147 AO
Type of data: Personnel files (general)
Retention period: 10 years after termination
Legal Basis: § 147 AO, § 257 HGB
Type of data: Tax / social security documents
Retention period: 10 years
Legal Basis: § 147 AO
Type of data: Employment references
Retention period: Employment references
Legal Basis: Limitation law
Type of data: Voluntary career data
Retention period: Until withdrawal or termination of employment
Legal Basis: Art. 7(3) GDPR
Type of data: Employee appraisals / performance reviews
Retention period: During the employment relationship; after termination up to 3 years; where tax or commercial law relevant up to 10 years
Legal Basis: § 195 BGB, § 61b ArbGG; where applicable § 147 AO, § 257 HGB; § 26 BDSG
Type of data: Time recording and absence data
Retention period: 10 years
Legal Basis: § 147 AO, § 257 HGB
Type of data: Pension / retirement provision data
Retention period: 10 years after termination of the insurance relationship
Legal Basis: Contractual provisions, Art. 28 GDPR
Type of data: Telephony connection data (RingCentral)
Retention period: Maximum 6 months
Legal Basis: Statutory retention obligations
Type of data: Call centre routing data (NICE)
Retention period: Maximum 30 days
Legal Basis: Operational necessity
Type of data: Microsoft 365 – work data
Retention period: After termination of employment in accordance with retention policies; tax/commercial law relevant content maximum 10 years
Legal Basis: § 147 AO, § 257 HGB
Note: Statutory retention obligations remain unaffected and may necessitate longer retention. After expiry of the retention periods, your data will be deleted or anonymised.
14. Data Protection for Applicants
Applicable to: all persons who apply to us
14.1 Purpose and Legal Bases
We process personal data of applicants exclusively for the purpose of carrying out the application procedure and deciding on the establishment of an employment relationship.
Legal bases:
- § 26(1) BDSG in conjunction with Art. 88 GDPR
- Art. 6(1)(b) GDPR (pre-contractual measures)
14.2 Application Channel: Workday
Applicants upload their documents directly to Workday.
Provider: Workday, Inc., 6110 Stoneridge Mall Road, Pleasanton, CA 94588, USA.
Data processed: Master data (name, date of birth), contact data (address, e-mail, telephone), application documents (CV, cover letter, certificates, qualifications), information on professional experience and education, salary expectations, earliest possible start date, information on work permit and immigration requirements where applicable, previous group affiliation, internal interview notes and evaluations.
Purpose: Carrying out the application procedure and deciding on the establishment of an employment relationship.
Hosting: USA.
Safeguards: DPF certification; SCC pursuant to Art. 46 GDPR; DPA pursuant to Art. 28 GDPR. See Section 1.4.
Note on special categories (Art. 9 GDPR): We ask that information on health, disability or similar characteristics only be provided if you expressly wish to do so.
14.3 Further Application Channels
Application by e-mail: Incoming application documents are reviewed by our HR team and then manually entered into Workday.
Application by post: Incoming documents are reviewed, scanned and manually entered into Workday. Upon request, we will return your documents or destroy them in accordance with our retention periods.
Recipients of application data: The entities required for decision-making, where applicable within the Group, e.g. HR, specialist department, legal department where applicable, IT and works council.
14.4 Headhunters and External Recruitment Agencies
DPAs pursuant to Art. 28 GDPR exist with instructed headhunters acting on our behalf. Independently responsible recruiting partners (e.g. job portals) are themselves responsible under data protection law. Applicants referred via headhunters are informed by us upon receipt of their data.
14.5 Third-Country Transfer and Intra-Group Sharing
Workday is DPF-certified; SCC and a DPA pursuant to Art. 28 GDPR are in place. Intra-group sharing is based on SCC and, where applicable, works agreements. See Section 1.4 for further information on third-country transfers.
14.6 Retention Periods – Applicant Data
Situation: Rejection / no contract concluded
Retention period: 6 months after completion of the procedure (§ 15(4) in conjunction with (1) AGG, § 22 AGG, § 61b(1) ArbGG)
Situation: Hiring
Retention period: Employee data pursuant to Section 13.5
15. Your Rights as a Data Subject
You have the following rights under the GDPR. For all enquiries and requests, please contact our Data Protection Officer (see Section 1.3).
15.1 Right of Access (Art. 15 GDPR)
You have the right to obtain from us confirmation as to whether personal data concerning you is being processed, and if so, access to that data. You may obtain free information about which data we store about you, where it originates, for what purposes we process it and to whom we disclose it.
15.2 Right to Rectification (Art. 16 GDPR)
You have the right to request the rectification of inaccurate or incomplete personal data. Should you find that data stored about you with us is inaccurate or incomplete, you may ask us to correct it.
15.3 Right to Erasure – "Right to be Forgotten" (Art. 17 GDPR)
You have the right to request that personal data concerning you be erased, in particular where:
- the data is no longer necessary for the purposes for which it was collected,
- you have withdrawn your consent and there is no other legal basis for the processing,
- you have objected to the processing,
- the data has been unlawfully processed,
- erasure is necessary to fulfil a legal obligation.
Exceptions: Erasure is not possible where the data is required to fulfil statutory retention obligations (e.g. tax and commercial law).
15.4 Right to Restriction of Processing (Art. 18 GDPR)
You have the right to request restriction of the processing of your personal data where:
- Accuracy contested: You contest the accuracy of your personal data stored with us. For the duration of the review, you have the right to request restriction of processing.
- Unlawful processing: The processing of your data is unlawful and you request restriction of use instead of erasure.
- Data required for legal claims: We no longer need your data, but you need it for the establishment, exercise or defence of legal claims.
- Objection lodged: You have lodged an objection pursuant to Art. 21(1) GDPR and it has not yet been determined whether our legitimate grounds override your interests.
Where processing has been restricted, such data may – apart from being stored – only be processed with your consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the EU or a Member State.
15.5 Right to Data Portability (Art. 20 GDPR)
You have the right to receive the personal data concerning you that you have provided to us, in a structured, commonly used and machine-readable format, and to transmit that data to another controller without obstruction from us.
Scope: This right applies to data processed on the basis of consent (Art. 6(1)(a) GDPR) or a contract (Art. 6(1)(b) GDPR).
15.6 Right to Object (Art. 21 GDPR)
Objection in special circumstances (Art. 21(1) GDPR)
Where we process your personal data on the basis of Art. 6(1)(e) or (f) GDPR (public interest or legitimate interest), you have the right at any time to object to that processing on grounds relating to your particular situation. This also applies to profiling based on those provisions. After an objection, we will no longer process your data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Objection to direct marketing (Art. 21(2) GDPR)
Where your personal data is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing; this also applies to profiling to the extent that it is related to such direct marketing. Upon objection, your data will no longer be used for the purposes of direct marketing.
15.7 Withdrawal of Consent (Art. 7(3) GDPR)
Many data processing operations are only possible with your explicit consent. You may withdraw consent already given at any time with effect for the future.
How to withdraw:
- By e-mail: Send an informal e-mail to datenschutzbeauftragter@enovis.com with the subject line "Withdrawal of consent" and state which consent you wish to withdraw
- By post: Write to the address of our Data Protection Officer stated above
- Cookie settings: For cookies, withdrawal can be made at any time via the cookie settings in the footer of our website
The lawfulness of data processing carried out up to the point of withdrawal remains unaffected.
15.8 Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data infringes the GDPR. Further information on the complaints procedure can be found in Section 16.
16. Complaints Procedure and Contact with the Supervisory Authority
16.1 Internal Complaints Procedure
Should you consider that we have violated data protection provisions, you may first contact our Data Protection Officer directly (see Section 1.3).
Our complaints procedure:
- Submission: Direct your complaint by e-mail or post to the Data Protection Officer (see Section 1.3).
- Confirmation: We will confirm receipt of your complaint without undue delay.
- Processing: We will process your complaint promptly, at the latest within 30 days, and inform you of the outcome.
- Further steps: Should you be dissatisfied with our handling, you may contact the supervisory authority (see Section 16.2).
16.2 Complaint with the Supervisory Authority
If you are dissatisfied with our handling or we do not respond, you have the right to contact the competent supervisory authority:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW)
P.O. Box 10 29 32
70025 Stuttgart
Telephone: +49 (0)711 615541-0
Fax: +49 (0)711 61 55 41 15
E-Mail: poststelle@lfdi.bwl.de
Web: www.lfdi.bwl.de
A complaint with the supervisory authority is free of charge and may also be lodged without prior complaint to us.
17. Final Notes
17.1 Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy at any time with effect for the future. A current version is available on our website at all times. Should material changes be made, we will inform you separately where required.
17.2 Status of this Privacy Policy
Last updated: May 2026
Version: 13
Ormed GmbH | Bötzinger Strasse 90 | 79111 Freiburg
Telephone: +49 (0)761 456601 | E-Mail: kundenservice@enovis.com | Web: www.enovis-medtech.de