PRIVACY POLICY
for www.inmed-personal.com
Last updated: 5 September 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:
inmed personal GmbH
Am Kühlen Grund 3A
87534 Oberstaufen
Germany
Represented by Managing Director Elitsa Seidel
Telephone: +49 6131 488 766 0
Email: info@inmed-personal.com
No data protection officer has been appointed. Please send data protection enquiries to the email address above.
2. General information on data processing
We process personal data only insofar as this is necessary to provide this website, respond to enquiries, take pre-contractual or contractual measures, provide our career advisory and placement services, or where you have given consent.
The relevant legal bases are, in particular, Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract or pre-contractual measures), Art. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(f) GDPR (legitimate interests). Special categories of personal data are processed only where an additional legal basis under Art. 9(2) GDPR applies, especially explicit consent.
We erase personal data when the purpose no longer applies and no statutory retention duty or overriding legal reason requires continued storage.
3. Hosting and server log data
We host our website with:
SuperHosting.BG Ltd.
5 Nikola Tesla Street, 4th floor
1574 Sofia
Bulgaria
Website: https://www.superhosting.bg
When you access the website, your browser transmits technically necessary information to the server. This may include your IP address, date and time of access, the requested page or file, referrer URL, browser type and version, operating system, amount of data transferred and access status.
Processing is necessary to deliver the website, maintain stability and security, and detect attacks or misuse. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and functional operation of our online service.
SuperHosting.BG processes website data on our behalf and in accordance with our instructions on the basis of a data processing agreement under Art. 28 GDPR. Processing takes place within the European Union. No third-country transfer is intended as part of regular hosting.
Server logs are kept only as long as necessary for security and error analysis, unless a security incident or legal obligation requires longer retention. Further information: https://en.superhosting.bg/web-hosting-page-privacy-policy.php
4. Encryption
This website uses TLS/SSL encryption. An encrypted connection can generally be recognised by “https://” in the browser address bar. This protects transmitted data against access by third parties; however, absolute security of internet transmission cannot be guaranteed.
5. Cookies and consent management with Complianz
Our website uses cookies and similar technologies. Some are strictly necessary for the operation of the website; others are used for preferences, statistics or marketing.
We use the WordPress plugin “Complianz – GDPR/CCPA Cookie Consent” to manage and document your choices. The legal bases are Art. 6(1)(c) and Art. 6(1)(f) GDPR; where access to the terminal device is strictly necessary, Section 25(2)(2) TDDDG applies.
Non-essential technologies are used only with your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR. You may withdraw or change your consent at any time through the cookie settings with future effect.
The language cookie “pll_language” stores your selected language. Its use is necessary to provide the language version requested by you and is based on Section 25(2)(2) TDDDG together with Art. 6(1)(f) GDPR. Under the current configuration it may remain stored for up to twelve months.
6. Contacting us
If you contact us by form, email or telephone, we process the data you provide, including your name, contact details, the content of your enquiry and any voluntary information, in order to respond and communicate with you.
Where the enquiry concerns a contract or pre-contractual steps, the legal basis is Art. 6(1)(b) GDPR. Otherwise, processing is based on Art. 6(1)(f) GDPR and our legitimate interest in dealing properly with business enquiries. Where consent is requested, Art. 6(1)(a) GDPR applies.
Forms are provided using the WordPress plugin “Contact Form 7”. Form data is transmitted to us and processed by our hosting and business email service providers. Where required, these providers act as processors under Art. 28 GDPR.
We erase enquiry data when the matter has been finally resolved and no business relationship arises, unless statutory retention duties or legitimate interests, such as the defence of legal claims, require continued storage.
7. Application and enquiry form
Through the application form, prospective candidates may provide their name, email address, telephone number, German-language level, preferred medical speciality and, voluntarily, a file. We process these data to assess the enquiry, provide advice, prepare or perform our services and contact the applicant.
The legal basis is Art. 6(1)(b) GDPR where processing is necessary for pre-contractual steps or a contract. Art. 6(1)(a) GDPR may additionally apply to voluntary information and documents. If documents contain special categories of data, we process them only where a basis under Art. 9(2) GDPR exists, especially explicit consent under Art. 9(2)(a) GDPR.
Data is not disclosed to hospitals, medical institutions or potential employers merely because the website form was submitted. Disclosure takes place only within the agreed placement process and on an applicable legal basis. Further details may be provided in a separate candidate privacy notice.
If no cooperation is established, we generally erase form data and documents no later than six months after the enquiry has been closed, unless consent to longer storage, a legal retention duty or an overriding legal reason applies.
8. Newsletter and information about vacancies
If you expressly consent, we use your email address to send information about vacancies, licensing, language and professional examinations, and our services. The legal basis is Art. 6(1)(a) GDPR. You may withdraw consent at any time with future effect via an unsubscribe link or by emailing info@inmed-personal.com.
For proof of consent, we may retain the time, email address, wording of the consent and technical verification data. The legal bases are Art. 6(1)(c) GDPR in conjunction with legal proof obligations and Art. 6(1)(f) GDPR. Newsletter data is processed until consent is withdrawn; proof of consent and withdrawal may be retained until the relevant limitation periods expire.
9. Embedded YouTube videos
Videos from YouTube are embedded on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Activating a video establishes a connection to Google servers. Google may process your IP address, device and browser information, the page visited and usage data. If you are signed into a Google account, Google may associate the visit with that account.
YouTube content is loaded only with your consent. The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR. You may withdraw consent at any time through the cookie settings.
Google may process data in third countries, including the United States. Transfers may be based on the EU-US Data Privacy Framework for certified recipients or on safeguards under Art. 46 GDPR. Further information: https://policies.google.com/privacy
10. Google Fonts
This website currently integrates fonts via Google Fonts, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When external font files are requested, a connection to Google servers may be established and your IP address may be processed.
External fonts are loaded only with your consent under Art. 6(1)(a) GDPR and, where information is stored on or accessed from your device, Section 25(1) TDDDG. Possible third-country transfers are governed by the safeguards described in the YouTube section. Further information: https://policies.google.com/privacy
11. Facebook content and Facebook SDK
A Facebook SDK or Facebook function is technically embedded on the website. The provider for users in the European Economic Area is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Loading or activating the function may transmit your IP address, device and browser data, the page visited and interaction data to Meta. If you are signed in to Facebook, Meta may associate the data with your account.
The function is loaded only with your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR. Consent can be withdrawn through the cookie settings. Meta may process data in the United States and other third countries. Transfers may be based on the EU-US Data Privacy Framework or safeguards under Art. 46 GDPR. Further information: https://www.facebook.com/privacy/policy/
No Meta Pixel was identified during the public technical review. If a Meta Pixel is activated, this policy must be amended beforehand and execution must be blocked until consent is obtained.
12. External links, social networks and WhatsApp
Our website contains links to external services, including Facebook, Instagram, LinkedIn, YouTube and, where applicable, WhatsApp. A standard link does not transmit data merely when our website is visited. When you click it, you leave our website and the relevant provider processes data under its own responsibility.
A WhatsApp link may open the WhatsApp app or web version. WhatsApp may process your telephone number as well as communication and metadata. The provider in the EEA is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Please use WhatsApp only if you agree to that processing. For confidential or extensive application documents, use email or another secure channel agreed with us.
13. Recipients and processors
Within our company, personal data is accessible only to staff who require it for the stated purposes. Selected hosting, IT, email, communication and website service providers may also receive data. Where they act on our behalf, we enter into the required agreements under Art. 28 GDPR.
Disclosure to hospitals or potential employers takes place within the placement service and in accordance with the separate candidate information or contractual arrangements. Data is not published or disclosed for other purposes without a legal basis.
14. Transfers to third countries
Individual services may transfer data outside the European Union or European Economic Area. Transfers take place only if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision, appropriate safeguards such as Standard Contractual Clauses, or a statutory exception. For US providers, we check whether a valid certification under the EU-US Data Privacy Framework exists. Different government access powers may nevertheless apply in third countries.
15. Retention period
Unless a specific period is stated above, we retain personal data only for as long as it is necessary for the relevant purpose. It is then erased or anonymised unless legal retention periods, consent or legitimate interests—particularly the establishment, exercise or defence of legal claims—justify further storage.
16. Your rights
Subject to the legal requirements, you have the right to access your data (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), withdrawal of consent with future effect (Art. 7(3)) and to lodge a complaint with a supervisory authority (Art. 77). To exercise your rights, contact info@inmed-personal.com. We may request appropriate proof of identity if there are reasonable doubts.
17. Right to object
Where we process personal data under Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. You may object to direct marketing at any time without giving reasons. Following an effective objection, we will no longer process the data for those purposes.
18. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority. The authority generally competent for our registered office is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
Website: https://www.lda.bayern.de
You may also contact another competent authority, particularly at your habitual residence or the place of the alleged infringement.
19. Automated decision-making
No solely automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place through this website.
20. Amendments
We update this privacy policy when the legal situation, website, services used or processing activities change. The version published on this website applies.