Data Privacy Statement
General Data Privacy Statement of cereneo
1. Introduction
1.1 General remarks & entities
At cereneo, we take the protection of your personal data very seriously. cereneo is aware that personal data may contain sensitive health data, which is particularly worthy of protection.
This General Data Privacy Statement (“Privacy Statement”) governs the personal data processing activities taking place between data subjects (“you”) and the entities of Neuro Recovery Group AG Seestrasse 18, 6354 Vitznau, Switzerland, CHE-164.807.282 (“NRG”), including:
- cereneo Schweiz AG, Hertensteinstrasse 162, 6353 Weggis, Switzerland (“CSAG”)
- cereneo Global Services AG, Seestrasse 18, 6354 Vitznau, Switzerland (“CGSAG”), and
- cereneo Prevention AG, Seestrasse 75, 6354 Vitznau, Switzerland (“CPAG”);
These entities process personal data in compliance with applicable data protection law, in particular the General Data Protection Regulation of the European Union ("GDPR"), the Swiss Federal Act on Data Protection ("FADP") and the Ordinance to the Federal Act on Data Protection ("OFADP") (collectively, the "Law").
The aforementioned cereneo entities are legal entities of NRG and in sections 1 and 2 are collectively or individually (as the context requires) referred to as “cereneo” or “we”. This Privacy Statement informs you regarding the collection, use and disclosure of your personal data, and your rights as a data subject.
1.2 Who is the Data Controller?
The NRG entity with which you have or may establish a contractual relationship (i.e., the entity you are assigned to as a customer/patient/accompanying person, or the entity your legal representative is engaged with) acts as the independent data controller for the relevant processing and is responsible for compliance.
Entity‑specific processing activities are described in sections 3 and following to this Privacy Statement.
If you have any questions regarding data privacy, please contact: datenschutz@cereneo.ch.
The external data protection officer of Neuro Recovery Group AG, CSAG, CGSAG, and CPAG is: heyData GmbH, Schützenstr. 5, 10117 Berlin, Germany, Email: anfragen@heydata.de.
2. Processing Operations Common to All NRG Entities
2.1 Data exchange within NRG
In connection with the provision of Services and administration, personal data may be exchanged between the various NRG entities listed above. Such exchanges arise from centrally performed administrative functions (e.g. HR, finance, billing) as well as the coordinated provision of medical, therapeutic and support services across NRG entities, where staff of one entity may need access to your data to ensure continuity and quality of care.
The legal basis for intra-NRG data exchanges is the performance of the contract (Art. 6 para. 1 lit. b GDPR) and, where applicable, legitimate interests (Art. 6 para. 1 lit. f GDPR).
2.2 Data exchange within PFG
To arrange and coordinate suitable accommodation and for related administrative purposes, certain personal data (including in particular name, contact details, length of stay and, where relevant, accessibility or dietary requirements) is passed on to certain companies of the Pühringer Foundation Group (“PFG”), a group of companies affiliated/connected through the same ultimate founder. Further information about PFG can be obtained from https://www.pf-group.org/.
The individual entities of PFG are listed further below. Access to your personal data by these entities is granted and controlled according to the "need-to-know" principle. In addition, it is contractually ensured that these entities only process the data in the way that the NRG entity that is your contractual partner is likely to do.
The legal basis for transfers to PFG entities for accommodation coordination is the performance of the contract (Art. 6 para. 1 lit. b GDPR).
2.3 Data processing in job applications
You can apply for a position at cereneo either spontaneously or in response to a specific job advertisement. In both cases, we will process the personal data you provide us with.
We use the data you provide us with to assess your application and suitability for employment. Application documents from unsuccessful applicants will be deleted at the end of the application process, unless you explicitly agree to a longer retention period or we are legally obliged to retain them for a longer period.
The legal basis for the data processing for this purpose is the execution of a contract (pre-contractual phase) within the meaning of Art. 6 para. 1 lit. b GDPR.
2.4 Data processing when you contact us
cereneo processes personal data you voluntarily provide (e.g. by email or telephone) to answer your questions, process requests, and provide requested information or services.
The legal basis for this processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR and, where applicable, the performance of a contract (Art. 6 para. 1 lit. b GDPR).
2.5 Newsletter / Marketing communication
If you register for our marketing emails or consent to receiving such communication (e.g. during your visit to an NRG entity website, during the onboarding process, etc.), the following data is collected and processed. Mandatory fields are marked with an asterisk (*):
- Email address
- Salutation
- First and last name
By registering, you consent to the processing of this data to receive marketing emails from us about products and services of the entire NRG group of companies. These marketing emails may also include invitations to provide feedback, or to rate our products and services. The collection of the salutation, first and last name allows us to associate the registration with any existing personal data about you and personalise the content of the marketing emails accordingly.
We will use your personal data to send marketing emails until you withdraw your consent. You can withdraw your consent at any time, in particular by using the unsubscribe link included in all marketing emails.
Our marketing emails may contain a web beacon, 1x1 pixel (tracking pixel), or similar technical tools. A web beacon is an invisible graphic that is linked to the user ID of the respective subscriber. For each marketing email sent, we receive information about which email addresses it was successfully delivered to, which email addresses have not yet received the marketing email, and which email addresses the delivery has failed for. It is also shown which email addresses have opened the marketing email and for how long, as well as which links have been clicked. Finally, we also receive information about subscribers who have unsubscribed from the mailing list. We use this data for statistical purposes and to optimize the frequency and timing of email delivery, as well as the structure and content of the marketing emails. This allows us to better tailor the information and offers in our marketing emails to the individual interests of the recipients.
The web beacon is deleted when you delete the marketing email. You can prevent the use of web beacons in our marketing emails by adjusting the settings of your email program so that HTML is not displayed in messages. You can find information on how to configure this setting in the help documentation of your email software application.
By subscribing to the marketing emails, you also consent to the statistical analysis of user behavior for the purpose of optimizing and customizing the marketing emails. The legal basis for this data processing is your consent within the meaning of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time.
We are also entitled to send marketing communication to our existing patients / customers based on our legitimate interest in the sense of Art. 6 para. 1 lit. f GDPR, e.g. without their consent. The recipients of this marketing communication are entitled to object to the marketing communication at any time for the future by using the unsubscribe link in the e-mails or by sending an e-mail to datenschutz@cereneo.ch.
2.6 Data processing when using our Wi-Fi Network
Patients, customers, accompanying persons and visitors in our premises have the possibility to use free of charge the Wi-Fi network operated by Facility Solutions Lake Lucerne AG, Seestrasse 23, 6354 Vitznau. When using the Wi-Fi network, data on the time and date of use, the network used, and the end device are recorded.
The legal basis for this processing is your consent within the meaning of Art. 6 para. 1 lit. a GDPR. You can revoke this consent at any time for the future.
2.7 Supplier Administration
cereneo processes the following categories of personal data in connection with the administration of business relationships with suppliers (including transactions and invoicing): Company name, first and last name of contact person, address, phone number, email address, residence information, payment information, transaction history, invoices.
The legal basis for this data processing is the preparation and/or fulfilment of the contract (Art. 6 para. 1 lit. b GDPR), exceptionally legitimate interests of cereneo in an accurate administration of the business relationship (Art. 6 para. 1 lit. f GDPR).
2.8 Management of data for billing purposes, appointment arrangements and other agreements
cereneo processes the following categories of personal data in connection with the administration of business relationships with other third parties, such as referring physicians, embassies and insurance companies, transportation service providers, partner companies, therapeutic and nursing services: Company name, first and last name of contact person, address, phone number, email address, residence information, payment information, transaction history, invoices.
The legal basis for this data processing is the preparation and/or fulfilment of the contract (Art. 6 para. 1 lit. b GDPR), exceptionally legitimate interests of cereneo in an accurate administration of the business relationship (Art. 6 para. 1 lit. f GDPR).
2.9 Transfer of data to third parties
cereneo only discloses personal data if either you have consented explicitly, if cereneo has a legal obligation to disclose or if it is required for the enforcement of rights and claims of cereneo. Data may also be disclosed if another company intends to acquire our company or parts thereof, and such disclosure is necessary to conduct a due diligence or to complete the transaction. The legal basis is either Art. 6 para. 1 lit. a GDPR (consent) or our legitimate interest (Art. 6 para. 1 lit. f GDPR).
In addition, cereneo will pass on personal data to third parties as far as it is necessary in the context of the use of NRG entity websites as well as the answering of questions, processing of inquiries or for the possible provision of services. The use of the data submitted by the third parties is strictly limited to the purposes described in this data privacy statement. The legal basis for this disclosure is Art. 6 para. 1 lit. b GDPR.
An overview of all third-party service providers is set out in the Third-Party Recipients list below. Additional service providers may explicitly be mentioned in this data privacy statement or also in the admission form to be signed by the patient / customer.
Where personal data constitutes confidential information falling within the scope of professional or medical secrecy, it will not be disclosed to third parties without the consent of the patient, unless such disclosure is permitted or required by law. Engagement of processors acting on our behalf under a data processing agreement does not constitute disclosure to a third party for the purposes of this paragraph.
Third-Party Recipients
Pühringer Foundation Group (PFG)
- POK Pühringer AG, Seestrasse 18, 6354 Vitznau, Switzerland
- Hospitality Visions Lake Lucerne AG, Seestrasse 18, 6354 Vitznau, Switzerland
- PFG Real Estate AG, Seestrasse 18, 6354 Vitznau, Switzerland
- Park Hotel Vitznau Weinarchiv AG, Seestrasse 18, 6354 Vitznau, Switzerland
- Facility Solutions Lake Lucerne AG, Seestrasse 23, 6354 Vitznau, Switzerland
- Neuro Music Academy AG, Seestrasse 75, 6354 Vitznau, Switzerland
- ZZ Vermögensberatung (Switzerland) AG, Seestrasse 18, 6354 Vitznau, Switzerland
Non-profit institutions
- Lake Lucerne Institute AG, Seestrasse 18, 6354 Vitznau, Switzerland, CHE-369.791.005
IT, software and data infrastructure
- Nexus Schweiz AG, Grenzstrasse 5a, 6214 Schenkon, Switzerland (clinical information system for CSAG, CGSAG)
- Zoho Corporation GmbH, Trinkausstr. 7, 40213 Düsseldorf, Germany (CRM, contact forms, marketing automation, analytics for CSAG and CGSAG)
- Reya Health Inc., 19863 Douglass Ln, Saratoga, CA 95070, United States (health information system CPAG)
- Mews Systems B.V., Vijzelstraat 68, 1017 HL Amsterdam, The Netherlands (property management, payments, contact data for CPAG)
- Abacus Research AG, Abacus-Platz 1, 9300 Wittenbach, Switzerland (accounting, CPAG)
- Agenza GmbH, Am Mattenhof 4a, 6010 Kriens, Switzerland (website development and maintenance for CSAG, CPAG)
Payment processing
- Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (website payments CSAG and CGSAG)
- Mews Systems B.V. (see above, also used for payment processing at CPAG)
- Worldline AG, Hardturmstrasse 201, 8005 Zürich, Switzerland (restaurant point-of-sale payments CPAG)
Appointment scheduling
- Calendly LLC, BB&T Tower, 271 17th St. NW, Atlanta, GA 30363, USA (CSAG website; CPAG App)
- OpenTable, Inc., 1 Montgomery Street, Suite 700, San Francisco, CA 94104, USA (CPAG restaurant reservation)
Communication and teletherapy
- Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Dublin 18, Ireland (CGSAG teletherapy)
- Twilio Ireland Limited, 70 Sir John Rogerson's Quay, Dublin 2, D02 R296, Ireland (OTP delivery CPAG App)
- Zoom Video Communications, Inc., 55 Almaden Boulevard, San Jose, CA 95113, USA (CPAG App video consultations)
Hosting and infrastructure
- Hostpoint AG, St. Dionysstrasse 31, 8640 Rapperswil-Jona, Switzerland
- Swiss IT Professional AG, Riethofstrasse 3, 8442 Hettlingen, Switzerland
- Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (JavaScript library delivery via unpkg.com)
- Linguise by DXT ONE, 32565 B Golden Lantern St, Suite 191, Dana Point, CA 92629, USA (website translation)
- Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Dublin 18, Ireland (Cloud infrastructure)
Analytics and marketing
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Analytics, Tag Manager, YouTube, Maps, Ads on the websites)
Social media
- Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
- LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
- WhatsApp Ireland Limited, Merrion Road, Dublin, Ireland
2.10 Central Data Storage and Analysis in the CRM system
If a clear identification of your person is possible, we will store and link the data described in this privacy statement, i.e. your personal information, contact details, contract data, and your browsing behavior on our websites, and any other data mentioned in this privacy statement in a central database. This allows for efficient management of personal data, enables us to adequately process your requests, and facilitates the efficient provision of the services you requested, as well as the performance of the related contracts.
The legal basis for this data processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in the efficient management of personal data.
We also analyze this data to further develop our products and services based on your needs and to provide you with the most relevant information and offers.
For the central storage and analysis of clinical and administrative data, as well as for invoicing and accounting purposes, CSAG and CGSAG use a software application provided by Nexus Schweiz AG, Grenzstrasse 5a, 6214 Schenkon, Switzerland (“Nexus”). Therefore, your data may be stored in a database of Nexus, which may allow Nexus to access your data if this is necessary for providing the software and supporting its use. Further information about data processing by Nexus can be found at https://www.nexus-ag.de/datenschutzerklaerung.
In addition, CSAG and CGSAG use CRM services of the company Zoho Corporation GmbH, Trinkausstr. 7, 40213 Düsseldorf, Germany (“Zoho”). Therefore, your data may be stored in a database of Zoho, which may allow Zoho to access your data if this is necessary for providing the software and supporting its use. Further information about data processing by Zoho can be found at https://www.zoho.com/privacy-commitment.html.
For accounting purposes, CPAG uses the accounting software Abacus, provided by Abacus Research AG, Abacus-Platz 1, 9300 Wittenbach, Switzerland. Personal data processed in this context includes contact data, invoicing addresses, invoice amounts, payment records and related financial correspondence. Further information about data processing by Abacus Research AG can be found at https://www.abacus.ch/datenschutz.
For the central storage and analysis of data, CPAG uses the hospital information system (HIS) provided by Reya Health Inc., 19863 Douglass Ln, Saratoga, CA 95070, United States (“Reya.ai”). Therefore, your data may be stored in a database, located in the EU, of Reya Health Inc., and may allow Reya Health Inc. to access your data if this is necessary for providing the software and supporting its use. Further information about data processing by Reya Health Inc. can be found at https://reya.ai/privacy/.
In addition, CPAG uses the property management system MEWS, provided by Mews Systems B.V., Vijzelstraat 68, 1017 HL Amsterdam, The Netherlands, including for invoicing and payment purposes. Therefore, your data may be stored in a database of Mews Systems B.V., which may allow Mews Systems B.V. to access your data if this is necessary for providing the software and supporting its use. Further information about data processing by Mews Systems B.V. can be found at https://www.mews.com/en/privacy-policy.
Information about data processing by third parties and any transfer abroad can be found in section 2.11 of this privacy statement.
2.11 Transfer of personal data abroad
cereneo is entitled to forward personal data to third parties and service providers abroad, provided that this is necessary to carry out the data processing described in this data privacy statement. In doing so, the statutory provisions for the transfer of personal data to third parties are complied with.
The countries to which data is transmitted include those that, according to the decision of the Federal Council and the European Commission, have an adequate level of data protection (such as the member states of the EEA or, from the EU's perspective, Switzerland), as well as those countries (such as the USA) whose level of data protection is not considered adequate (see Annex 1 of the Data Protection Ordinance (DPO) and the website of the European Commission). If the country in question does not provide an adequate level of data protection, we ensure that your data is adequately protected by these companies by means of appropriate safeguards, unless an exception is specified on a case-by-case basis for the individual data processing (see Art. 49 of the GDPR). Unless otherwise specified, these safeguards may be provided for by standard contractual clauses as referred to in Art. 46(2)(c) of the GDPR, which can be found on the websites of the Federal Data Protection and Information Commissioner (FDPIC) and the EU Commission. If you have any questions regarding the implemented measures, please reach out to our data protection contact person at datenschutz@cereneo.ch.
Most of the third-party service providers have their domiciles in the neighbouring countries.
Some of the third-party service providers mentioned in this Privacy Statement are, however, based in the USA. For the sake of completeness, we would like to inform users residing or based in Switzerland or the EU that certain third-party service providers mentioned in this privacy statement are located in the USA. It is important to note that there are surveillance measures by US authorities in place that generally allow for the storage of all personal data of individuals whose data has been transmitted from Switzerland or the EU to the United States. This occurs without differentiation, limitation, or exception based on the purpose for which the data is being collected and without an objective criterion that would restrict US authorities' access to the data and its subsequent use to specific, strictly limited purposes that can justify the interference associated with accessing and using the data. Furthermore, we would like to point out that affected individuals from Switzerland or the EU do not have legal remedies or effective judicial protection against general access rights of US authorities, which would allow them to access the data concerning them and to rectify or delete it. We explicitly highlight this legal and factual situation to enable you to make an informed decision regarding your consent to the use of your data.
For data subjects residing in Switzerland or a member state of the EU, we also want to inform you that, from the perspective of the European Union and Switzerland, the United States does not provide an adequate level of data protection, among other reasons, as explained in this paragraph. In cases where we have mentioned in this privacy statement that data recipients (such as Google) are located in the United States, we will ensure through contractual arrangements with these companies and, if necessary, additional appropriate safeguards, that your data is adequately protected at our third-party service providers.
2.12 Entitlement to disclosure, deletion, correction and data portability
If the legal requirements are met, you have the following rights with respect to data processing:
- Information right: You have the right at any time to request access to your personal data stored by us. This gives you the opportunity to check which personal data we process about you and that we use it in accordance with applicable data protection regulations.
- Correction right: You have the right to have inaccurate or incomplete personal data corrected and to be informed of the correction. We will inform the individual concerned of the adjustments made to any incorrect data, unless such notification is impossible or involves a disproportionate effort.
- Deletion right: You have the right to require us to delete your personal data, as long as there is no legal basis that allows us to further process such data.
- Right to limitation of processing: If GDPR applies to the data processing, you have the right, under certain conditions, to request the processing of your personal data to be restricted.
- Data transferability rights: Under certain circumstances you have the right to receive from us the personal data that you have provided to us, free of charge and in a readable format.
- Right to complain: You have the right to lodge a complaint with a competent supervisory authority, e.g., against the manner in which your personal data is processed.
- Right of revocation: You can withdraw your consent to certain data processing at any time, with effect for the future.
- Right to object: You can object to certain data processing at any time. For this, you contact datenschutz@cereneo.ch.
2.13 Data retention
cereneo stores personal data for as long as it is necessary to achieve the data processing purposes mentioned above. Contract data is retained by cereneo for a longer period, as this is prescribed by legal retention obligations.
Personal data collected as part of the performance of services in Switzerland is retained for 10 years, unless it is foreseeable or already known that the underlying treatment will become the subject of a legal dispute. In this case, the retention period is extended to a period of 20 years.
Retention duties, which oblige cereneo to store data, furthermore result from regulations on accounting and tax law. According to these regulations, business communications, contracts concluded and accounting records must be stored for up to 10 years. If cereneo no longer needs any such data to perform the services for the users, the data will be blocked. This means that the data may then exclusively be used for accounting and tax purposes.
2.14 Data security
cereneo uses appropriate technical and organizational security measures to protect personal data against manipulation, partial or total loss and against unauthorized access by third parties. These safety measures are continuously improved according to the technological development.
3. Scope and purpose of the collection, processing and use of personal data on the websites
3.1 Website operators
CSAG and CPAG each maintain their respective websites: www.cereneo.ch (hereinafter individually referred to as the "CSAG website") and www.cereneo-prevention.com (hereinafter individually referred to as the "CPAG website"). The CSAG website includes information on the business activities of CGSAG.
Where the processing activities apply to both CSAG and CPAG websites, these are collectively referred to as the “websites” or “we”. CSAG and CPAG are the independent data controllers and responsible for the collection, processing and use of personal data, collected from or provided for by the visitors of their respective website (hereinafter “user“ or “you“) in line with the Law.
Certain information provided by the user to us may be confidential and therefore falls under the scope of professional or medical secrecy in line with applicable Law. Although we implement the highest security measures for the transmission and storage of data, we do recommend you to not transmit such confidential information through the websites and to keep such information as general as possible. You can however share patient information, as to which it is hereafter explicitly mentioned that it can be submitted.
3.2 When accessing the websites
While visiting the websites, the server temporarily stores each access in a log file. Until the automatic deletion, the IP address of the requesting computer, date and time of the access, the name and the URL of the retrieved file, the websites from which the access took place and the operating system used by user’s computer and the browser used by the user as well as the country, from where the user has accessed among other things, will be automatically collected.
The collection and processing of these data are generally anonymized without personal reference for the following purposes:
- to enable the use of the websites (connection establishment);
- to guarantee permanently the system security and stability; and
- to optimize the internet offer as well as for internal statistical purposes.
The information mentioned above will not be linked or stored with personal data.
Only in the case of an attack on our net infrastructures or in case of suspicion of an illegal use or misuse of any of the websites the IP-address will be analyzed for investigation and defense purposes and potentially used in the course of a criminal proceeding for the identification and for civil and criminal law actions against the respective user.
We rely on our legitimate interests within the meaning of Art. 6 para. 1 lit. f. GDPR to process the data for these purposes.
3.3 Contact form on the websites
We collect and process personal data in this context only where users voluntarily provide it, for example through the contact form, by email or by telephone. Such data is processed solely for the purpose of responding to the relevant inquiry or request.
The legal basis for this processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR and, where applicable, the performance of a contract (Art. 6 para. 1 lit. b GDPR). Users can object to this data processing at any time (see contact data above).
For handling contact requests through a contact form, CSAG and CGSAG use a software application provided by Zoho Corporation GmbH, Trinkausstr. 7, 40213 Düsseldorf, Germany. Therefore, your data may be stored in a database of Zoho Corporation, which may allow Zoho Corporation to access your data if this is necessary for providing the software and supporting its use. Information about data processing by third parties and any transfers abroad can be found further below this data privacy statement.
For handling contact requests through a contact form, CPAG currently uses the WordPress backend of the CPAG website, operated by Agenza GmbH, Am Mattenhof 4a, 6010 Kriens, Switzerland. Contact data submitted via the form is stored in the WordPress database and processed from there for the purpose of responding to the inquiry. Information about data processing by third parties and any transfers abroad can be found in section 2.11.
3.4 Cookies on the websites
In order to make the visit of the websites attractive and to enable the use of certain functions, so-called cookies are enabled on the websites. The cookies are small text files, which are stored on the user’s device. Some of the installed cookies are automatically deleted after the end of the browser session (so-called session cookies). Other cookies remain on the user’s device and allow us to recognize the browser on the next visit (persistent cookies).
We use cookies for various purposes that are necessary for the desired use of the websites, i.e., "technically necessary." Cookies are also used for security purposes, such as preventing the unauthorized posting of content. Finally, we use cookies in the design and programming of our websites, for example, to enable the uploading of scripts or codes.
The legal basis for this data processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in providing user-friendly and up-to-date websites.
To the extent required by Law, we will obtain the user's prior consent before placing any cookies on its device, such as tracking or marketing cookies. The legal basis for this data processing is Art. 6 para. 1 lit. a GDPR.
We hereby inform the users that certain cookies which do not require prior consent are already set as soon as a user accesses the websites. Users can, however, set up the browser in such a way that they are informed of the setting of cookies and may decide individually about their acceptance or can exclude the acceptance of cookies for certain cases or in general. The non-acceptance or de-activation of functional or technical cookies may restrict the functionality of the websites.
Browsers allow the users to control the storage of cookies on their respective devices. The description for the respective browsers can be found at the following links:
- Internet Explorer™: http://windows.microsoft.com/de-DE/windows-vista/Block-or-allow-cookies
- Safari™: https://support.apple.com/de-ch/guide/safari/ibrw850f6c51/mac
- Chrome™: http://support.google.com/chrome/bin/answer.py?hl=de&hlrm=en&answer=95647
- Firefox™: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
- Opera™ : http://help.opera.com/Windows/10.20/de/cookies.html
3.5 Appointment booking via Calendly on CSAG website
CSAG offers you the possibility to make an appointment with us in a simple and uncomplicated way. For this purpose CSAG uses "Calendly". Calendly is a service of Calendly LLC, BB&T Tower, 271 17th St. NW, Atlanta, GA 30363.
When you use Calendly, personal data such as your name, email address and telephone number, as well as any other information you may provide when requesting an appointment, are processed. This data is processed by Calendly. The use is voluntary and is based solely on your consent in accordance with Art. 6 para. 1 lit. a GDPR.
Cookies of the provider Calendly are used when using the online appointment booking. If you do not want your data to be processed by Calendly and thereby transmitted to the USA, please choose another way to make an appointment with us.
This Privacy Statement and the privacy policy of Calendly apply to the use of Calendly and the associated data transfers. You can find them at: https://calendly.com/pages/privacy. Furthermore, Calendly has published additional information on compliance with the GDPR at https://help.calendly.com/hc/en-us/articles/360007032633-GDPR-FAQs.
3.6 Use of Stripe as payment service provider on CSAG website
Payments via CSAG website are processed via the technical service provider "Stripe". Payment processing is carried out via the payment service provider Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
Only the data provided during the ordering process will be passed on in accordance with Art. 6 para. 1 lit. b GDPR (name, address, account number, bank code, if applicable, credit card number, invoice amount, currency and transaction number). Your data will only be used for the purpose of payment processing with the payment service provider Stripe Payments Europe Ltd. and only to the extent necessary. You can find more information about Stripe's data protection at: https://stripe.com/gb/privacy.
3.7 Analytical Tools
For the purpose of customizing and continuously optimizing our websites, we use the web analytics services listed below. In this context, pseudonymized usage profiles are created, and cookies are used (please also see section 3.4). The information generated by the cookie regarding your use of our websites is usually transmitted to a server of the service provider, where it is stored and processed, together with the Log File Data mentioned in section 3.2. This may also result in a transfer to servers abroad, e.g., the USA (for information on the absence of an adequate level of data protection and the proposed safeguards, see section 2.11).
Through data processing, we obtain, among others, the following information:
- navigation path followed by a visitor on the site (including content viewed, products selected or purchased, or services booked);
- time spent on websites or specific pages;
- the specific page from which the websites is left;
- the country, region, or city from where an access is made;
- end device (type, version, color depth, resolution, width, and height of the browser window); and
- returning or new visitor.
The provider, on our behalf, will use this information to evaluate the use of the websites, in particular, to compile websites activity reports and provide further services related to websites usage and internet usage for the purposes of market research and the customization of the websites. For these processing activities, we and the providers may be considered joint controllers in terms of data protection to a certain extent.
The legal basis for this data processing with the following services is your consent within the meaning of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent or oppose to processing at any time by rejecting or deactivating the relevant cookies in the settings of your web browser (see section 3.4) or by using the service-specific options described below.
Regarding the further processing of the data by the respective provider as the (sole) controller, including any potential disclosure of this information to third parties, such as authorities due to national legal regulations, please refer to the respective privacy policy of the provider. In addition to the analytics services described in this section, certain technical infrastructure components used on the websites (see sections 3.7.3 and 3.7.4) may also transmit technical data in connection with the delivery of website content.
3.7.1 Google Analytics on the websites
We use the web analytics service Google Analytics provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, or Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (Google).
Contrary to the description in the general section above, IP addresses are not logged or stored in Google Analytics (in the version used here, "Google Analytics 4"). For accesses originating from the EU, IP address data is only used to derive location data and is immediately deleted thereafter. When collecting measurement data in Google Analytics, all IP searches take place on EU-based servers before the traffic is forwarded to Analytics servers for processing. Google Analytics utilizes regional data centers. When connecting to the nearest available Google data center in Google Analytics, the measurement data is sent to Analytics via an encrypted HTTPS connection. In these centers, the data is further encrypted before being forwarded to Analytics' processing servers and made available on the platform. The most suitable local data center is determined based on the IP addresses. This may also result in a transfer of data to servers abroad, e.g., the USA (for information on the absence of an adequate level of data protection and the proposed safeguards, see section 2.11).
We also use the technical extension called "Google Signals", which enables cross-device tracking. This makes it possible to associate a single website visitor with different devices. However, this only happens if the visitor is logged into a Google service during website visits and has activated the "personalized advertising" option in their Google account settings. Even in such cases, we do not have access to any personal data or user profiles; they remain anonymous to us. If you do not wish to use "Google Signals," you can deactivate the "personalized advertising" option in your Google account settings.
Users can prevent the collection of data related to their usage (including IP address) generated by the cookie as well as the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en-GB.
The transfer of your personal data to Google is based on our data processing agreement (in connection with Art. 28 GDPR / Art. 9 FADP).
3.7.2 Zoho PageSense on CSAG website
CSAG uses Zoho PageSense, a service of Zoho Corporation, Trinkausstr. 7, 40213 Düsseldorf, Germany, to run A/B tests, heatmaps and funnel analyses and thereby improves the usability and performance of CSAG website. PageSense uses cookies (see section 3.4) and processes usage data such as pages viewed, click and scroll behaviour, time spent, device/browser information and the test variant shown, and creates aggregated reports.
The transfer of your personal data to Zoho is based on CSAG’s data processing agreement (in connection with Art. 28 GDPR / Art. 9 FADP).
Further information about data processing by Zoho can be found at https://www.zoho.com/privacy-commitment.html.
3.7.3 JavaScript libraries via unpkg.com on the websites
The websites load JavaScript libraries via unpkg.com, a public content delivery network. Requests to unpkg.com are routed through the infrastructure of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. When the websites access unpkg.com, technical data including your IP address, browser information (User-Agent), the referring website URL and the time of the request may be transmitted to and processed by Cloudflare's servers. This processing is technically necessary to ensure proper functionality of the websites.
The legal basis for this processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in ensuring the technical functionality of the websites. As Cloudflare is based in the United States, transfers of personal data are subject to section 2.11 of this Privacy Statement. Cloudflare has implemented standard contractual clauses to ensure an adequate level of data protection. Further information about data processing by Cloudflare can be found at https://www.cloudflare.com/privacypolicy/.
3.7.4 Website translation via Linguise on the websites
The websites use Linguise, a translation service provided by Linguise by DXT ONE, 32565 B Golden Lantern St, Suite 191, Dana Point, CA 92629, USA, to offer content in multiple languages. When the translation function is used, technical data including your IP address, browser information (User-Agent), the referring website URL and the time of the request may be processed by Linguise.
The legal basis for this processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in providing accessible, multilingual website content. As Linguise is based in the United States, transfers of personal data are subject to section 2.11 of this Privacy Statement. Further information about data processing by Linguise can be found at https://www.linguise.com/data-processing-agreement/.
3.8 Marketing Tools
We use services of various companies to provide users with interesting offers online. In the process of doing this, user behavior on our websites and websites of other providers is analyzed to subsequently be able to show users online advertising that is individually tailored to the users.
Most technologies for tracking user behavior (Tracking) and displaying targeted advertising (Targeting) utilize cookies (see also section 3.4), which allow users' browser to be recognized across different websites. Depending on the service provider, it may also be possible for users to be recognized online even when using different end devices (e.g., laptop and smartphone). This may be the case, for example, if users access a service across multiple devices.
In addition to the data already mentioned, which is collected when visiting websites (Log File Data, see section 3.2) and by cookies (section 3.4) and which may be transmitted to the companies involved in the advertising networks, the following data, in particular, is used to select the advertising that is potentially most relevant to you:
- information about users that users provided when registering or using a service from advertising partners (e.g., gender, age group); and
- user behavior (e.g., search queries, interactions with advertisements, types of websites visited, products or services viewed and purchased, newsletters subscribed to).
We and our service providers use this data to determine whether users belong to the target audience we address and take this into account when selecting advertisements. For example, after visiting our websites, users may see advertisements for the products or services users have viewed when they visit other sites (Re-targeting). Depending on the amount of data, a user profile may also be created, which is automatically analyzed; the advertisements are then selected based on the information stored in the profile, such as belonging to certain demographic segments or potential interests or behaviors. These advertisements may be displayed to users on various channels, including our websites or app (as part of on- and in-app marketing), as well as advertising placements provided through the online advertising networks we use, such as Google.
The data may then be analyzed for the purpose of settlement with the service provider, as well as for evaluating the effectiveness of advertising measures to better understand the needs of our users and customers and to improve future campaigns. This may also include information that the performance of an action (e.g., visiting certain sections of our websites or submitting information) can be attributed to a specific advertising. We also receive from service providers aggregated reports of advertisement activity and information on how users interact with our websites and advertisements.
The legal basis for this data processing is users' consent within the meaning of Art. 6 para. 1 lit. a GDPR. Users can withdraw their consent at any time by rejecting or deactivating the relevant cookies in the settings of their web browser (see section 3.4). Further options for blocking advertising can also be found in the information provided by the respective service provider, such as Google.
3.8.1 Google AdWords Conversion-Tracking on the websites
We use the offer of Google Ads Conversion provided by Google Ireland Limited, Google Building Gordon House, Barrow St, Dublin 4, Ireland, to draw attention to our attractive offers by means of advertising material (so-called Google Ads) on external websites. In relation to the data of the advertising campaigns, we can determine how successful the individual advertising measures are. In this way, we pursue the interest of displaying advertising that is of interest to users, making our websites more interesting for users and achieving a fair calculation of advertising costs.
These advertising materials are delivered by Google via so-called "Ad Servers". For this purpose, we use Ad Server Cookies, through which certain parameters can be measured to measure success, such as the display of the ads or clicks by users. If users reach our websites via a Google ad, Google Ads will store a cookie on their end device. For this cookie, the unique cookie ID, number of ad impressions per placement (frequency), last impression (relevant for post-view conversions) and opt-out information (marking that the user no longer wishes to be addressed) are usually stored as analysis values.
The cookies enable Google to recognize users' internet browser. If a user visits certain pages of an ad client's website and the cookie stored on their computer has not expired, Google and the client may recognize that the user clicked on the ad and was redirected to that page. A different cookie is assigned to each AdSense client. Cookies cannot be tracked through the websites of ad clients. We ourselves do not collect and process any personal data in the advertising measures mentioned. We only receive statistical evaluations from Google. These evaluations enable us to identify which of the advertising measures used are particularly effective. We do not receive any further data from the use of the advertising material, in particular we cannot identify the users on the basis of this information.
Due to the marketing tools used, users' browsers automatically establish a direct connection with the Google server. We have no influence on the scope and further use of the data collected by Google through the use of these tools and therefore inform users according to our state of knowledge: through the integration of Ads Conversion, Google receives the information that users have called up the corresponding part of our websites or clicked on an advertisement from us. If users are registered with a Google service, Google can assign the visit to their account. Even if users are not registered with Google or have not logged in, it is possible that the provider will find out their IP address and save it.
Users can find additional information about the conversion-tracking at https://support.google.com/google-ads/answer/1722022.
Users may prevent this tracking by rejecting or de-activating cookies (see section 3.4).
It cannot entirely be excluded that certain personal data be transferred to servers abroad, e.g., the USA (for information on the absence of an adequate level of data protection and the proposed safeguards, see section 2.11).
The transfer of your personal data to Google is based on our data processing agreement (in connection with Art. 28 GDPR / Art. 9 FADP).
3.8.2 Google Tag Manager on the websites
We use the Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The Google Tag Manager is a tool that allows us to integrate tracking or statistical tools and other technologies on our websites. The Google Tag Manager itself does not create user profiles, does not store cookies and does not perform any independent analyses. It only serves to manage and play out the tools integrated via it. However, the Google Tag Manager collects your IP address, which may also be transferred to Google's parent company in the United States.
For details about Google’s data processing, please refer to: https://policies.google.com/privacy. Google may process personal data outside the EU/EEA.
We safeguard the transfer of personal data via standard contractual clauses (see section 2.11).
The transfer of your personal data to Google is based on our data processing agreements (in connection with Art. 28 GDPR / Art. 9 FADP).
3.8.3 Affiliate programme and partner tracking
cereneo cooperates with selected partner and distribution affiliates. If you reach our websites via an individual affiliate link, we store information enabling us to attribute your visit to the relevant partner. For this purpose, we process in particular the affiliate or partner identifier, the time of the visit, the pages accessed and, where applicable, information submitted in connection with an inquiry or booking. Attribution takes place via URL parameters and technical tracking mechanisms (e.g. session or cookie technologies).
This processing serves to measure the performance of our affiliate partners, to attribute inquiries and bookings, to settle partner commissions, and to analyse and optimise our sales and marketing activities. In the context of affiliate tracking, a cookie containing an anonymous partner identifier may be stored on your device; its maximum storage duration is 90 days. Affiliate data is retained only for as long as necessary for these purposes or for the duration of applicable statutory retention obligations.
The legal basis for this processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in operating and optimising our partner programme. Where the affiliate cookie is not technically necessary, we obtain your prior consent in accordance with Art. 6 para. 1 lit. a GDPR (see section 3.4).
Where affiliate partners are located outside Switzerland or the EEA, the provisions of section 2.11 apply.
3.8.4 Zoho Marketing Automation on CSAG website
CSAG uses Zoho Marketing Automation. The provider is Zoho Corporation GmbH, Trinkausstr. 7, 40213 Düsseldorf, Germany. Zoho Marketing Automation is a tool that allows CSAG to manage campaigns, mailing lists and evaluate the effectiveness of CSAG’s online marketing. For this purpose, Zoho may process contact data, campaign metadata, and website interaction data collected via cookies (see section 3.4).
The transfer of your personal data to Zoho is based on CSAG’s data processing agreement (in connection with Art. 28 GDPR / Art. 9 FADP).
Further information about data processing by Zoho can be found at https://www.zoho.com/privacy-commitment.html.
3.9 YouTube on the websites
The websites embed videos from YouTube, a service operated by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in extended data protection mode. According to YouTube, this mode prevents YouTube from storing information about visitors before they watch a video. However, data transfers to YouTube's partner networks, including Google DoubleClick, may still occur regardless of whether a video is played.
When a user starts a YouTube video, a connection to YouTube's servers is established, which may include information about the page visited. If the user is logged into their YouTube account at that time, YouTube may associate this activity with their personal profile. Users can prevent this by logging out of their YouTube account before using the websites.
YouTube may also store cookies or use comparable recognition technologies (e.g. device fingerprinting) on the user's device. This information may be used for video analytics, improving user experience and fraud prevention. Additional data processing activities beyond our control may be triggered once a video is started.
The legal basis for embedding YouTube is our legitimate interest in providing informative content to website visitors (Art. 6 para. 1 lit. f GDPR). Where consent is required, it will be obtained separately and can be withdrawn at any time. Further information about Google's data processing can be found at https://policies.google.com/privacy.
3.10 Google Maps on the websites
The websites use Google Maps, a mapping service provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Maps enables us to display interactive map content and to provide website users with convenient geographic orientation and directions to our locations.
When users access a page in which Google Maps is integrated, a connection to the servers of Google is automatically established. In this context, Google receives information about which website pages users have visited and may process additional technical data, such as users’ IP address, browser information, device settings, location data (if enabled on the device), and interaction data with the embedded map. If users are logged into their Google account, Google may assign this information directly to their personal profile. Users can prevent such association by logging out of their Google account before accessing the map.
Google may store cookies or use similar tracking technologies (e.g., device fingerprinting) on users’ end devices in connection with the provision of Google Maps. These technologies can be used, among other things, to ensure the proper display of map content, maintain security and functionality of the service, and analyze service use for optimization and personalization purposes. Additional data processing activities may be triggered once the Google Maps content is fully loaded, which are beyond our control.
The use of Google Maps is based on our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in providing an appealing and user‑friendly presentation of our locations and in facilitating navigation for the website users.
Please find further information about Google Maps at https://policies.google.com/privacy?hl=en.
3.11 Social Media on websites
The websites contain links to profiles on the social networks of the following providers:
- Meta operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, https://www.facebook.com/privacy/policy/;
- LinkedIn operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, https://www.linkedin.com/legal/privacy-policy;
- WhatsApp operated by WhatsApp Ireland Limited, Merrion Road, Dublin, Ireland, https://www.whatsapp.com/legal/privacy-policy-eea;
- YouTube operated by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland, https://policies.google.com/privacy?hl=en.
Share functions (plugins) are deactivated by default, so no data is sent to the social networks when a user simply accesses the websites. We have integrated the plugins in such a way that a connection to the social networks' servers is not automatically established. A connection is only established when a user actively clicks on a profile link or share button, thereby giving their consent to the transmission and further processing of data by the respective provider.
When a user clicks on any social network element, their browser establishes a direct connection with that network's servers. The network receives information about the page visited and the user's IP address. This information is transmitted directly to a server of the provider and stored there. Transfers of data to servers in the USA may occur; section 2.11 applies. We have no influence over the scope of data collected by the providers through these interactions.
If the user is logged into their social network account at the time of clicking, the network may associate this activity directly with their profile. To prevent this, users should log out of their account before interacting with any social network element on the websites.
If users interact with a share button, the corresponding information is transmitted to the provider's servers. Content shared by the user (for example, indicating an interest in a product or service) may be published on the social network and displayed to other users. The provider may use this information for advertising and personalisation purposes, including the creation of usage, interest and relationship profiles, to evaluate browsing behaviour on the websites in connection with advertisements shown on the social network, and to provide other services associated with use of the network. For details on the scope of data collection, further processing, and users' rights, please refer to the privacy policies of the respective providers.
The legal basis for profile links is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in maintaining and promoting our social media presence. The legal basis for share functions is consent within the meaning of Art. 6 para. 1 lit. a GDPR. Users can withdraw their consent at any time in accordance with the instructions provided by the relevant provider.
3.12 Providers in connection with the websites
For an overview of all third-party providers whose services are used in connection with the websites, please refer to the Third-Party Recipients list in section 2.9.
4. Specific Data Processing CSAG
Unless expressly stated otherwise in this section, the information in section 2 applies without modification.
4.1 Medical and therapeutic treatment (incl. offer administration and patient onboarding)
CSAG may process the following categories of personal data of patients and, if applicable, their accompanying persons and/or (legal) representatives:
- Personal data which the patients or their legal representatives provide to CSAG within the framework of the offer, upon entry or registration (e.g. personal master data, doctor's reports of prior treatment, clinical pictures, medical documents, contact data of contact person; lead source; wishes of the patient; possible entry and exit dates, referrer; visa information, insurance information; religion; treating physician (incl. contact address));
- Personal data which CSAG receives from third parties with the consent of the patient (e.g. travel and accommodation information, medical records and medical documents from third-party service providers consulted; laboratory examination reports);
- Financial data prepared by CSAG for the offer (estimated data), such as expected turnover, possible entry and exit dates, planned monthly amount, probability of entry; or
- Personal data collected during treatment (e.g. clinical pictures, prescribed therapies and therapy results, diagnostic/assessment/imaging material, reports, recording of training progress as well as the withdrawal report and accounts).
CSAG may, with the approval of the patient, organize medical examinations with third party specialists. For this purpose, CSAG may disclose to these specialists the information required for such an examination, such as contact details of the patient, medical reports, etc.
CSAG may, with the approval of the patient, request third parties to provide specific services, such as transport services. For this purpose, CSAG may disclose to these third parties the information required for the provision of the requested services.
CSAG may use third-party tools, devices and applications for diagnostic, therapeutic and monitoring purposes. These include, among others, devices and systems for neurological assessment and stimulation (e.g. EEG, EMG, evoked potentials, tDCS/tES, vagus nerve stimulation), movement and rehabilitation therapy (e.g. robotic therapy systems, functional electrical stimulation, exoskeletons, treadmill and balance systems), cardiorespiratory and sleep monitoring (e.g. ECG/Holter, polysomnography, pulse oximetry, CPAP monitoring, blood pressure monitoring), imaging and radiology (e.g. MRI/PACS, teleradiology), infusion and medication systems, and digital therapy applications.
For these purposes, the following categories of personal data are typically entered and processed: name, date of birth, weight and height, as well as data on therapy progress and clinical measurements. The providers of these tools and applications may independently collect and process further data in connection with their use. CSAG is responsible only for the careful selection of such tools and for the clinical activities over which it has direct control.
For invoicing purposes, CSAG processes the contact data, invoicing address, and the invoice amount of the patients.
The legal basis for this data processing is the preparation and/or fulfilment of the contract (Art. 6 para. 1 lit. b GDPR), exceptionally legitimate interests of CSAG (Art. 6 para. 1 lit. f GDPR) as well as, where applicable, the consent of the patients given in the admission form or via specific individual consent.
4.2 Data exchange with Lake Lucerne Institute
For the purpose of the advancement and improvement of therapeutic approaches as well as for the review, the measurement and the evaluation of the rehabilitation progress, CSAG cooperates with Lake Lucerne Institute AG (LLUI), a charitable, non-profit stock corporation under Swiss law founded in 2021. The patient will primarily be cared for by employees of CSAG. Sensitive personal data of the patient (for example measurements regarding the development of the locomotor system) will be collected for the purposes mentioned above, also after the stay in the clinic. The employees of CSAG or LLUI may contact the patient for that purpose.
CSAG provides LLUI with access to the patient files in order to process the personal data contained therein for the purposes mentioned above. The data collected from or about the patient in connection with the aforementioned purposes will be stored on servers of CSAG. CSAG ensures that LLUI will process the sensitive personal data collected from or about the patient (including the data in the patient file) solely in a manner that would also be permitted to CSAG in accordance with this data privacy statement and the Law.
For the purposes mentioned above, CSAG and LLUI, respectively, may suggest the use of (software) applications - including mobile applications - of third party service providers (for example, teletherapy applications, which compose patient data by means of smartphone measurements and forward these data to CSAG, or applications that allow communication between CSAG and LLUI, respectively, and the patient and that assist with the scheduling of visits). The final decision about the use of such applications remains with the patient. CSAG is not responsible for the collection and processing of personal data by such applications. Instead, responsibility is with the provider of the respective application. It is the responsibility of the patient to gather necessary information about the data processing by such applications.
5. Specific Data Processing CGSAG
5.1 Teletherapy and home-based services
Unless otherwise agreed with the patient or their (legal) representative, teletherapy and home-based services are carried out by CGSAG, a company of the Neuro Recovery Group, on the basis of an independent contractual relationship with the patient or their (legal) representative. Personal data of patients treated by CSAG that, after discharge from the inpatient facility of CSAG, decide to continue treatment through teletherapy and/or home-based services, will be transferred from CSAG to CGSAG to the extent that such personal data is required for the continuation of the treatment, which includes the personal data mentioned in section 4.1 of this data privacy statement.
In connection with teletherapy services, CGSAG primarily uses Microsoft Teams, a service provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Dublin 18, Ireland (part of Microsoft Corporation). Personal data transmitted during teletherapy sessions (including name, image, voice and session content) may be processed by Microsoft. Data may be transferred to Microsoft's global infrastructure, including servers outside the EU/EEA, in which case the provisions of section 2.11 apply. Microsoft has implemented standard contractual clauses to ensure an adequate level of data protection. Further information about data processing by Microsoft can be found at https://privacy.microsoft.com.
The legal basis for this data processing is the preparation and/or fulfilment of the contract (Art. 6 para. 1 lit. b GDPR), exceptionally legitimate interests of CGSAG (Art. 6 para. 1 lit. f GDPR) as well as, where applicable, the consent of the patients given in the admission form or via specific individual consent.
5.2 Consulting Services
CGSAG can offer consulting services, such as installing equipment in a patient's home.
CGSAG may process personal data for the purpose of providing such consulting services including identification data (e.g., name, first name, postal address). The legal basis for the data processing is the preparation and/or fulfilment of the contract (Art. 6 para. 1 lit. b GDPR) to which the data subject is party.
6. Specific Data Processing CPAG
CPAG provides (i) prevention / longevity / health services (including medical and therapeutic services, as applicable) and (ii) hospitality services (e.g., accommodation, restaurant service, health & lifestyle services, gym & spa services, and other hotel-type services).
6.1 Prevention Services and Therapeutic Services (Preventive / Outpatient)
CPAG provides prevention, longevity and health‑oriented services aimed at supporting customers in maintaining or improving their well‑being, lifestyle, and general health status. These services include, but are not limited to, preventive assessments, lifestyle analyses, personalised prevention programmes, longevity consultations, nutrition‑related guidance, sleep and regeneration support, stress‑management activities, movement and exercise programmes.
In addition to prevention services, CPAG may provide therapeutic services in the field of neurology and general health. These services include, but are not limited to, doctor consultations, and comprehensive medical diagnostics.
In connection with the provision of these services, CPAG processes the following categories of personal data of customers and, if applicable, their accompanying persons and/or (legal) representatives:
- Personal data which the customers or their legal representatives provide to CPAG within the framework of the offer, upon entry or registration (e.g. personal master data, reports of prior treatment, medical documents, contact data of contact person; lead source; wishes of the customer; possible entry and exit dates, referrer; visa information, insurance information; religion; treating physician (incl. contact address));
- Personal data which CPAG receives from third parties with the consent of the customer (e.g. travel and accommodation information, medical records and medical documents from third-party service providers consulted; laboratory examination reports);
- Financial data prepared by CPAG for the offer (estimated data), such as expected turnover, possible entry and exit dates, planned monthly amount, probability of entry; or
- Personal data collected during the performance of the services (e.g. prescribed treatments and treatment results, diagnostic/assessment/imaging material, reports, recording of training progress as well as the withdrawal report and accounts).
CPAG may, with the approval of the customer, organize services and/or medical examinations with third party specialists. For this purpose, CPAG may disclose to these specialists the information required for such a service or examination, such as contact details of the customer, treatment reports, medical reports, etc.
CPAG may use for the treatment of customers third party tools and applications. For these purposes, the following categories of personal data are typically entered and processed: Name of customer, date of birth, weight & height. Data on training and treatment progress is also collected and processed. The providers of the tools and applications may collect and process further data about the use of their tools and applications.
Additionally, CPAG may, with the approval of the customer, request third parties to provide specific services, such as transport services. For this purpose, CPAG may disclose to these third parties the information required for the provision of the requested services.
For invoicing purposes, CPAG processes the contact data, invoicing address, and the invoice amount of the customers.
The legal basis for this data processing is the preparation and/or fulfilment of the contract (Art. 6 para. 1 lit. b GDPR), exceptionally legitimate interests of CPAG (Art. 6 para. 1 lit. f GDPR) as well as, where applicable, the consent of the customers given in the admission form or via specific individual consent.
6.2 Hospitality Services (Accommodation, Restaurant, Gym & Spa, Guest Services)
CPAG processes personal data for the purpose of providing hospitality services, including accommodation, food and beverage services, access to gym and spa facilities, and related guest services. The categories of personal data processed include identification data (e.g., salutation, first name, surname, email address, phone number), financial information (e.g., bank account information, payment method), reservation and booking details (e.g., room type, length of stay, number of guests, arrival and departure times) and any preferences or special requests communicated by the customer (e.g., dietary requirements, accessibility needs, room preferences).
The legal basis for this data processing is the performance of a contract (Art. 6 para. 1 lit. b GDPR) to which the customer is party. Where additional preferences are provided voluntarily and are not necessary for the provision of the booked services, the legal basis is the customer's consent pursuant to Art. 6 para. 1 lit. a GDPR.
For property management, reservation processing and payment processing in connection with accommodation and other CPAG services, CPAG uses MEWS, provided by Mews Systems B.V., Vijzelstraat 68, 1017 HL Amsterdam, The Netherlands. Further information about data processing by Mews Systems B.V. can be found at https://www.mews.com/en/privacy-policy.
For the management of restaurant reservations, CPAG uses OpenTable, a service provided by OpenTable, Inc., 1 Montgomery Street, Suite 700, San Francisco, CA 94104, USA. Personal data processed includes name, email address, telephone number, party size and any special requests. As OpenTable is based in the United States, transfers of personal data are subject to section 2.11 of this Privacy Statement. OpenTable has implemented standard contractual clauses to ensure an adequate level of data protection. Further information: https://www.opentable.com/legal/privacy-policy.
For restaurant point-of-sale payment processing, CPAG uses Worldline, a payment service provided by Worldline AG, Hardturmstrasse 201, 8005 Zürich, Switzerland. Personal data processed in this context includes payment card data and transaction details, which are processed solely for the purpose of completing the payment transaction. Further information about data processing by Worldline can be found at Privacy Notice public website Worldline SA | Worldline Global.
6.3 CERENEO PREVENTION App
CPAG operates the CERENEO PREVENTION application ("App") and is the data controller responsible for personal data collected and processed through it. CPAG processes such data in accordance with this Privacy Statement and applicable data protection law, including where relevant the Swiss Telecommunications Act (TCA).
As part of the App we enable you to use and display, in particular, the following information:
- Unified Health Dashboard: Centralized overview of health, lifestyle, and longevity data in one platform.
- Wearable Integration: Syncs with devices such as Apple Watch, Fitbit, Oura, and other trackers to collect real-time data (activity, sleep, stress, etc.).
- Personalized Health Goals: Daily goals and recommendations based on individual health data.
- Nutrition & Meal Tracking: Log meals (including photo-based logging) with automated nutritional analysis.
- Appointment Management: Book, reschedule, or cancel appointments directly within the app.
- Secure Messaging: Encrypted chat functionality for communication with healthcare professionals.
- Digital Forms & Documentation: Access and complete medical forms and required documents within the app.
The following subsections describe the specific data processing activities associated with individual App features and the third-party services integrated into the App. You can access this Privacy Statement within the App at any time via: Home screen > Hamburger Menu > About & Settings > About > Privacy Policy.
6.3.1 Downloading and Accessing the App
When you download the App, the relevant app store provider (e.g., Apple App Store / Google Play) processes personal data such as your account identifier, time of download, and mobile device identifiers. The app store provider acts as an independent controller for this processing. We do not control their processing. Please consult their privacy notices:
- Google Play Store (Android): Google LLC., 1600 Amphitheatre Parkway, Mountain View, California 94043, USA: https://policies.google.com/privacy?hl=en&gl=de
- App Store (iOS): Apple Inc., One Apple Park Way, Cupertino, California, USA, 95014: https://www.apple.com/legal/privacy
6.3.2 App Permissions
To enable core App functions, the App may request access permissions such as Bluetooth, location services, and notifications. Where you grant such permissions, you can revoke them at any time in your mobile device settings. If you revoke permissions that are necessary for a feature, that feature may not function properly.
6.3.3 Push Notifications / Token Data
If you enable push notifications, your mobile device operating system generates a unique notification token (e.g., Apple Push Notification Service / Google Firebase Cloud Messaging) which is processed to deliver notifications to your mobile device. We use the token to (i) deliver service/technical notifications (e.g., firmware, battery or feature alerts) and, where you have consented, (ii) deliver marketing notifications. You can disable push notifications at any time in your mobile device settings and/or in the App.
6.3.4 Cookies
Cookies help in many ways to make the use of our App easier, more enjoyable and more meaningful. Cookies are information files that your web browser automatically saves on your device's hard drive when you visit our App. In particular, we use technically necessary cookies, performance cookies, and functional cookies.
We use these cookies, for example, to temporarily store your entries when filling out a form on the App, so that you do not have to repeat the entry when calling up another subpage. Cookies may also be used to identify you as an authorised and registered user after you register on the App, without you having to log in again when you visit another page.
Usually cookies are accepted automatically. However, you can disable the function so that no cookies are stored on your device or a message always appears when you receive a new cookie.
Disabling cookies may prevent you from using all features of our App.
6.3.5 Tracking
We may use tracking tools for the purpose of designing and continuously optimising our App to meet your needs. In this context, pseudonymised user profiles are created and small text files stored on your device ("cookies") are used. The information generated by the cookies about your use of our App is transferred to the servers of the provider of these services, stored there and processed for us. In addition, we may receive the following information:
- navigation path of a user,
- time spent on the App,
- the country, region or city from which access is made,
- the device (type, version, colour depth, resolution, width and height of the browser window), and
- if you are a recurring or new user.
The information is used to evaluate the use of the App, to compile reports on App activity and to provide other services related to the use of the App and the internet for purposes of market research and need-based design of this App. In addition, this information may be transferred to third parties if this is required by Law or if third parties process this data on our behalf.
The legal basis for this data processing is your consent within the meaning of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time in the App settings.
6.3.6 Google Maps
For location-based features within the App, CPAG uses Google Maps. The provisions of section 3.10 of this Privacy Statement apply accordingly.
6.3.7 Appointment scheduling via Calendly
For scheduling onboarding calls and appointments in connection with the App, CPAG uses Calendly, a service of Calendly LLC, BB&T Tower, 271 17th St. NW, Atlanta, GA 30363, USA. Personal data such as your name, email address and telephone number are processed by Calendly when you book an appointment. As Calendly is based in the United States, transfers of personal data are subject to section 2.11 of this Privacy Statement. Further information: https://calendly.com/pages/privacy.
6.3.8 One-time password delivery via Twilio
For the delivery of one-time passwords (OTPs) used for authentication within the App, CPAG uses Twilio, a service provided by Twilio Ireland Limited, 70 Sir John Rogerson's Quay, Dublin 2, D02 R296, Ireland. Personal data processed includes your phone number and the OTP. The legal basis is the performance of a contract (Art. 6 para. 1 lit. b GDPR). Further information about data processing by Twilio can be found at https://www.twilio.com/en-us/legal/privacy.
6.3.9 Video consultations via Zoom
For video-based consultations conducted through the App, CPAG uses Zoom, a service provided by Zoom Video Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. Personal data transmitted during video sessions (including name, image, voice and session content) may be processed by Zoom. As Zoom is based in the United States, transfers of personal data are subject to section 2.11 of this Privacy Statement. Zoom has implemented standard contractual clauses to ensure an adequate level of data protection. Further information: https://explore.zoom.us/en/privacy.
Last changed in July 2026