Data Privacy Policy
cereneo's privacy policy
1. Introduction
1.1 General Information & Companies
At cereneo, we take the protection of your personal data very seriously. cereneo is aware that personal data may contain particularly sensitive health data that requires special protection.
This General Data Protection Policy ("Data Protection Policy") governs the processing of personal data between data subjects ("you") and the companies of Neuro Recovery Group AG, Seestrasse 18, 6354 Vitznau, Switzerland, CHE-164.807.282 ("NRG"), including:
- cereneo Schweiz AG, Hertensteinstrasse 162, 6353 Weggis, Switzerland («CSAG»);
- cereneo Global Services AG, Seestrasse 18, 6354 Vitznau, Switzerland (“CGSAG”); and
- cereneo Prevention AG, Seestrasse 75, 6354 Vitznau, Switzerland («CPAG»).
These companies process personal data in accordance with applicable data protection law, in particular the General Data Protection Regulation of the European Union (“GDPR”), the Swiss Federal Act on Data Protection (“FADP”) and the Ordinance to the Federal Act on Data Protection (“OFADP”) (together the “Law”).
The aforementioned cereneo companies are NRG companies and are referred to individually or collectively as "cereneo" or "we" in sections 1 and 2, depending on the context. This privacy policy informs you about the collection, use, and disclosure of your personal data, as well as your rights as a data subject.
1.2 Who is the responsible body?
The NRG company with which you have or may enter into a contractual relationship (i.e., the company to which you are assigned as a customer, patient/accompanying person, or the company with which your legal representative is in contact) acts as an independent responsible body for the respective processing and is responsible for compliance.
Company-specific processing is described in sections 3 ff. of this privacy policy.
For questions regarding data protection, please contact: datenschutz@cereneo.ch.
The external data protection officer for Neuro Recovery Group AG, CSAG, CGSAG and CPAG is: heyData GmbH, Schützenstr. 5, 10117 Berlin, Germany, Email: anfragen@heydata.de.
2. Processing applicable to all NRG companies
2.1 Data exchange within the NRG
In connection with the provision of services and administration, personal data may be exchanged between the various NRG companies listed above. Such exchange arises from centrally provided administrative functions (e.g., HR, finance, billing) as well as from the coordinated provision of medical, therapeutic, and support services across the NRG companies, whereby employees of one company may require access to your data to ensure continuity and quality of care.
The legal basis for data exchange within NRG is the performance of a contract (Art. 6 para. 1 lit. b GDPR) and, where applicable, the legitimate interest (Art. 6 para. 1 lit. f GDPR).
2.2 Data exchange within the PFG
For the organization and coordination of suitable accommodation, as well as for related administrative purposes, certain personal data (in particular name, contact details, length of stay, and, where relevant, needs relating to accessibility or diet) will be shared with certain companies within the Pühringer Foundation Group ("PFG"), a group of companies linked by the same founder. Further information about the PFG can be found at [link to PFG website] https://www.pf-group.org/.
The individual companies within the PFG group are listed below. These companies' access to your personal data is granted and controlled according to the "need-to-know" principle. Furthermore, it is contractually ensured that these companies process the data only in the same way that the NRG company, your contractual partner, would likely do so.
The legal basis for the transfer to PFG companies for the coordination of accommodation is the performance of the contract (Art. 6 para. 1 lit. b GDPR).
2.3 Data processing in applications
You can apply to cereneo either spontaneously or in response to a specific job posting. In both cases, we process the personal data you provide.
We use the data you provide to review your application and suitability for employment. Application documents of unsuccessful applicants will be deleted after the application process is completed, unless you expressly consent to a longer retention period or we are legally obligated to retain them for a longer period.
The legal basis for data processing for this purpose is the performance of the contract (pre-contractual phase) within the meaning of Art. 6 para. 1 lit. b GDPR.
2.4 Data processing when contacting us
Cereneo processes personal data that you voluntarily provide (e.g. via email or telephone) in order to answer your questions, process requests and provide requested information or services.
The legal basis for this processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR and, where applicable, the performance of a contract (Art. 6 para. 1 lit. b GDPR).
2.5 Newsletter / Marketing Communication
When you register for our marketing emails or consent to receiving such communications (e.g., during your visit to an NRG website, during the onboarding process, etc.), the following data will be collected and processed. Required fields are marked with an asterisk (*):
- E-mail address
- Salutation
- First and Last Name
By registering, you consent to the processing of this data in order to receive marketing emails from us about products and services from the entire NRG Group. These marketing emails may also contain requests for feedback or reviews of our products and services. Collecting your title, first name, and last name allows us to link your registration with any existing personal data we may have about you and to personalize the content of the marketing emails accordingly.
We use your personal data to send you marketing emails until you withdraw your consent. You can withdraw your consent at any time, in particular via the unsubscribe link included in all marketing emails.
Our marketing emails may contain a web beacon, a 1x1 pixel (tracking pixel), or similar technical tools. A web beacon is an invisible graphic linked to the user ID of the respective subscriber. For each marketing email sent, we receive information about which email addresses were successfully delivered, which email addresses have not yet received the marketing email, and which failed delivery. We also see which email addresses opened the marketing email and for how long, as well as which links were clicked. Finally, we also receive information about subscribers who have unsubscribed from the mailing list. We use this data for statistical purposes and to optimize the frequency, timing, structure, and content of our marketing emails. This allows us to better tailor the information and offers to the individual interests of the recipients.
The web beacon is deleted when you delete the marketing email. You can prevent the use of web beacons by adjusting your email program's settings to block HTML from being displayed in messages. Refer to your email application's help documentation for configuration instructions.
By subscribing to marketing emails, you also consent to the statistical analysis of user behavior for the purpose of optimizing and tailoring the marketing emails. The legal basis for this data processing is your consent in accordance with Article 6(1)(a) GDPR. You can withdraw your consent at any time.
We are also entitled to send marketing communications to our existing patients/customers based on our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR, e.g., without their consent. Recipients of these marketing communications are entitled to object to them at any time for the future by using the unsubscribe link in the emails or by sending an email to datenschutz@cereneo.ch.
2.6 Data processing when using our WLAN network
Patients, clients, accompanying persons, and visitors to our premises have the option of using the Wi-Fi network operated by Facility Solutions Lake Lucerne AG, Seestrasse 23, 6354 Vitznau, free of charge. When using the Wi-Fi network, data regarding the time and date of use, the network used, and the device used will be recorded.
The legal basis for this processing is your consent within the meaning of Article 6(1)(a) GDPR. You can withdraw this consent at any time with effect for the future.
2.7 Supplier Management
In connection with the management of business relationships with suppliers (including transactions and invoicing), cereneo processes the following categories of personal data: company name, first and last name of contact person, address, telephone number, email address, residence information, payment information, transaction history, invoices.
The legal basis for this data processing is the preparation and/or fulfillment of the contract (Art. 6 para. 1 lit. b GDPR), exceptionally the legitimate interest of cereneo in the correct management of the business relationship (Art. 6 para. 1 lit. f GDPR).
2.8 Management of data for billing purposes, appointment scheduling and other agreements
In connection with the management of business relationships with other third parties, such as referring physicians, embassies and insurance companies, transport service providers, partner companies and therapeutic and nursing services, cereneo processes the following categories of personal data: company name, first and last name of contact person, address, telephone number, email address, residence information, payment information, transaction history, invoices.
The legal basis for this data processing is the preparation and/or fulfillment of the contract (Art. 6 para. 1 lit. b GDPR), exceptionally the legitimate interest of cereneo in the correct management of the business relationship (Art. 6 para. 1 lit. f GDPR).
2.9 Disclosure of data to third parties
Cereneo only discloses personal data if you have given your explicit consent, if Cereneo is legally obligated to disclose it, or if this is necessary to enforce Cereneo's rights and claims. Data may also be disclosed if another company intends to acquire our company or parts thereof, and such disclosure is necessary for conducting due diligence or completing the transaction. The legal basis for this is either Article 6(1)(a) GDPR (consent) or our legitimate interest (Article 6(1)(f) GDPR).
Furthermore, cereneo discloses personal data to third parties to the extent necessary in connection with the use of the NRG websites, answering questions, processing inquiries, or providing any services. The use of data transmitted by third parties is strictly limited to the purposes described in this privacy policy. The legal basis for this disclosure is Article 6(1)(b) GDPR.
An overview of all third-party service providers can be found in the list of third-party recipients below. Further service providers may be explicitly named in this privacy policy or in the admission form to be signed by the patient or client.
Insofar as the personal data is confidential information subject to professional or medical confidentiality, this information will not be disclosed to third parties without the patient's consent, unless such disclosure is permitted or required by law. The use of data processors acting on our behalf does not constitute disclosure to third parties for the purposes of this paragraph.
Third-party recipients
Pühringer Foundation Group (PFG)
- POK Pühringer AG, Seestrasse 18, 6354 Vitznau, Switzerland
- Hospitality Visions Lake Lucerne AG, Seestrasse 18, 6354 Vitznau, Switzerland
- PFG Real Estate AG, Seestrasse 18, 6354 Vitznau, Switzerland
- Park Hotel Vitznau Weinarchiv AG, Seestrasse 18, 6354 Vitznau, Switzerland
- Facility Solutions Lake Lucerne AG, Seestrasse 23, 6354 Vitznau, Switzerland
- Neuro Music Academy AG, Seestrasse 75, 6354 Vitznau, Switzerland
- ZZ Vermögensberatung (Switzerland) AG, Seestrasse 18, 6354 Vitznau, Switzerland
Non-profit institutions
- Lake Lucerne Institute AG, Seestrasse 18, 6354 Vitznau, Switzerland, CHE-369.791.005
IT, software and data infrastructure
- Nexus Schweiz AG, Grenzstrasse 5a, 6214 Schenkon, Switzerland (clinical information system for CSAG, CGSAG)
- Zoho Corporation GmbH, Trinkausstr. 7, 40213 Düsseldorf, Germany (CRM, contact forms, marketing automation, analytics for CSAG and CGSAG)
- Reya Health Inc., 19863 Douglass Ln, Saratoga, CA 95070, USA (Health Information System CPAG)
- Mews Systems BV, Vijzelstraat 68, 1017 HL Amsterdam, Netherlands (Property Management, Payments, Contact Details for CPAG)
- Abacus Research AG, Abacus-Platz 1, 9300 Wittenbach, Switzerland (Accounting, CPAG)
- Agenza GmbH, Am Mattenhof 4a, 6010 Kriens, Switzerland (Website development and maintenance for CSAG, CPAG)
Payment processing
- Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (Website Payments CSAG and CGSAG)
- Mews Systems BV (see above, also for payment processing at CPAG)
- Worldline AG, Hardturmstrasse 201, 8005 Zurich, Switzerland (Restaurant POS Payments CPAG)
Scheduling
- Calendly LLC, BB&T Tower, 271 17th St. NW, Atlanta, GA 30363, USA (CSAG website; CPAG app)
- OpenTable, Inc., 1 Montgomery Street, Suite 700, San Francisco, CA 94104, USA (CPAG Restaurant Reservation)
Communication and teletherapy
- Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Dublin 18, Ireland (CGSAG Teletherapy)
- Twilio Ireland Limited, 70 Sir John Rogerson's Quay, Dublin 2, D02 R296, Ireland (OTP delivery CPAG app)
- Zoom Video Communications, Inc., 55 Almaden Boulevard, San Jose, CA 95113, USA (CPAG app video consultations)
Hosting and infrastructure
- Hostpoint AG, St. Dionysstrasse 31, 8640 Rapperswil-Jona, Switzerland
- Swiss IT Professional AG, Riethofstrasse 3, 8442 Hettlingen, Switzerland
- Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (delivery of JavaScript libraries via unpkg.com)
- Linguise by DXT ONE, 32565 B Golden Lantern St, Suite 191, Dana Point, CA 92629, USA (Website translation)
- Microsoft Ireland Operations Limited, One Microsoft Place, Leopardstown, South County Business Park, Dublin 18, Ireland (cloud infrastructure)
Analytics and Marketing
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Analytics, Tag Manager, YouTube, Maps, Ads on websites)
Social Media
- Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
- LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
- WhatsApp Ireland Limited, Merrion Road, Dublin, Ireland
2.10 Central data storage and analysis in the CRM system
Provided that it is possible to clearly identify you, we store and link the data described in this privacy policy—i.e., your personal information, contact details, contract data, and your browsing behavior on our websites, as well as all other data mentioned in this privacy policy—in a central database. This enables efficient management of personal data, appropriate processing of your requests, efficient provision of the services you have requested, and fulfillment of the associated contracts.
The legal basis for this data processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in the efficient management of personal data.
We also analyze this data to further develop our products and services according to your needs and to provide you with the most relevant information and offers.
For the central storage and analysis of clinical and administrative data, as well as for billing and accounting purposes, CSAG and CGSAG use a software application from Nexus Schweiz AG, Grenzstrasse 5a, 6214 Schenkon, Switzerland ("Nexus"). Therefore, your data may be stored in a Nexus database, which allows Nexus to access your data when necessary for providing the software and supporting its use. Further information on data processing by Nexus can be found at [link to Nexus privacy policy] https://www.nexus-ag.de/datenschutzerklaerung.
Furthermore, CSAG and CGSAG use CRM services provided by Zoho Corporation GmbH, Trinkausstr. 7, 40213 Düsseldorf, Germany ("Zoho"). Therefore, your data may be stored in a Zoho database, which allows Zoho to access your data when necessary for providing the software and supporting its use. Further information on data processing by Zoho can be found at [link to Zoho's privacy policy] https://www.zoho.com/privacy-commitment.html.
For accounting purposes, CPAG uses the Abacus accounting software from Abacus Research AG, Abacus-Platz 1, 9300 Wittenbach, Switzerland. Personal data processed in this context includes contact details, billing addresses, invoice amounts, payment records, and related financial correspondence. Further information on data processing by Abacus Research AG can be found at [link to Abacus Research AG's privacy policy] https://www.abacus.ch/datenschutz.
For the central storage and analysis of data, CPAG uses the hospital information system (HIS) of Reya Health Inc., 19863 Douglass Ln, Saratoga, CA 95070, USA ("Reya.ai"). Therefore, your data may be stored in a database located in the EU and operated by Reya Health Inc., which allows Reya Health Inc. to access your data when necessary for providing the software and supporting its use. Further information on data processing by Reya Health Inc. can be found at [link to Reya Health Inc. privacy policy] https://reya.ai/privacy/.
Furthermore, CPAG uses the MEWS property management system from Mews Systems BV, Vijzelstraat 68, 1017 HL Amsterdam, Netherlands, for billing and payment purposes, among others. Therefore, your data may be stored in a Mews Systems BV database, which allows Mews Systems BV to access your data when necessary for providing the software and supporting its use. Further information on data processing by Mews Systems BV can be found at [link to privacy policy] https://www.mews.com/en/privacy-policy.
Information on data processing by third parties and on any transfers abroad can be found in section 2.11 of this privacy policy.
2.11 Transfer of personal data abroad
Cereneo is authorized to transfer personal data to third parties and service providers abroad, insofar as this is necessary for carrying out the data processing described in this privacy policy. The legal regulations governing the transfer of personal data to third parties will be observed.
The countries to which data is transferred include those that, according to the Federal Council and the European Commission, have an adequate level of data protection (such as the EEA member states or, from the EU's perspective, Switzerland), as well as countries (such as the USA) whose level of data protection is considered inadequate (see Annex 1 of the Data Protection Ordinance (DSV) and the European Commission's website). If the country in question does not offer an adequate level of data protection, we ensure, through appropriate safeguards, that your data is adequately protected by these companies, unless an exception applies to the specific data processing in question (see Art. 49 GDPR). Unless otherwise stated, these safeguards may be provided by standard contractual clauses within the meaning of Art. 46 para. 2 lit. c GDPR, which are available on the websites of the Federal Data Protection and Information Commissioner (FDPIC) and the EU Commission. If you have any questions about the implemented measures, please contact our data protection officer at [contact information missing in original text] datenschutz@cereneo.ch.
Most third-party service providers are based in neighboring countries.
Some of the third-party service providers mentioned in this privacy policy are based in the USA. For the sake of completeness, we would like to inform users residing or based in Switzerland or the EU that certain third-party service providers mentioned in this privacy policy are located in the USA. It should be noted that US authorities have surveillance measures in place that generally permit the storage of all personal data of individuals whose data has been transferred from Switzerland or the EU to the United States. This occurs without differentiation, limitation, or exception based on the purpose of the data collection and without any objective criteria that would restrict US authorities' access to and subsequent use of the data to specific, strictly limited purposes that could justify the interference associated with such access and use. Furthermore, we would like to point out that data subjects in Switzerland or the EU have neither legal remedies nor effective judicial protection against the general access rights of US authorities that would allow them to access, rectify, or erase their data. We expressly draw your attention to this legal and factual situation so that you can make an informed decision about your consent to the use of your data.
For individuals residing in Switzerland or an EU member state, we would also like to point out that, from the perspective of the European Union and Switzerland, the United States does not offer an adequate level of data protection, for reasons including those set out in this paragraph. In cases where we have mentioned in this privacy policy that data recipients (such as Google) are located in the United States, we ensure, through contractual agreements with these companies and, where necessary, through additional appropriate safeguards, that your data is adequately protected by our third-party service providers.
2.12 Right to information, erasure, rectification and data portability
Provided the legal requirements are met, you have the following rights regarding data processing:
- Right to information: You have the right to request information about your personal data stored by us at any time. This allows you to check which personal data we process about you and that we use it in accordance with applicable data protection regulations.
- Right of rectification: You have the right to have inaccurate or incomplete personal data corrected and to be informed of the correction. We will inform the data subject of the corrections made to inaccurate data, unless this proves impossible or involves a disproportionate effort.
- Right to erasure: You have the right to request that we delete your personal data, as long as there is no legal basis that allows us to continue processing it.
- Right to restrict processing: Insofar as the GDPR is applicable to data processing, you have the right, under certain conditions, to request a restriction of the processing of your personal data.
- Right to data portability: Under certain circumstances, you have the right to receive the personal data you have provided to us free of charge and in a readable format.
- Right to appeal: You have the right to lodge a complaint with a competent supervisory authority, e.g. against the way your personal data is processed.
- Right of withdrawal: You can withdraw your consent to certain data processing activities at any time with effect for the future.
- Right to object: You can object to certain data processing activities at any time. To do so, please contact us datenschutz@cereneo.ch.
2.13 Storage
Cereneo stores personal data for as long as necessary to achieve the aforementioned processing purposes. Contractual data is retained by Cereneo for a longer period, as required by statutory retention obligations.
Personal data collected in Switzerland during the provision of services will be stored for 10 years, unless it is foreseeable or already known that the underlying processing will be the subject of legal proceedings. In this case, the retention period is extended to 20 years.
Cereneo is also subject to data retention obligations arising from accounting and tax regulations. These regulations require business communications, concluded contracts, and accounting documents to be retained for up to 10 years. If cereneo no longer requires such data to provide its services, the data will be blocked. This means that the data may then only be used for accounting and tax purposes.
2.14 Data security
Cereneo uses appropriate technical and organizational security measures to protect personal data against manipulation, partial or complete loss, and unauthorized access by third parties. These security measures are continuously improved in line with technological developments.
3. Scope and purpose of the collection, processing and use of personal data on the websites
3.1 Website operators
CSAG and CPAG each operate their own website: www.cereneo.ch (hereinafter referred to individually as the "CSAG website") and www.cereneo-prevention.com (hereinafter referred to individually as the "CPAG website"). The CSAG website contains information about CSAG's business activities.
Insofar as the processing relates to both the CSAG and CPAG websites, these are collectively referred to as "websites" or "we". CSAG and CPAG are each independent data controllers and are responsible for the collection, processing, and use of personal data collected or provided by visitors to their respective websites (hereinafter "users" or "you"), in accordance with the law.
Certain information you submit may be confidential and therefore subject to professional or medical confidentiality under applicable law. Although we implement the highest security measures for the transmission and storage of data, we recommend that you do not submit such confidential information via the websites and that you keep any such information as general as possible. However, you may submit patient data only as expressly indicated below.
3.2 When accessing the websites
When you visit the website, the server temporarily stores each access in a log file. Until automatic deletion, the following information is automatically recorded: the IP address of the requesting computer, the date and time of access, the name and URL of the retrieved file, the website from which the access originated, the operating system and browser used by the user's computer, and the country from which the access was made.
The collection and processing of this data is generally carried out anonymously without reference to individuals for the following purposes:
- to enable the use of the websites (establishing a connection);
- to ensure system security and stability on a permanent basis; and
- to optimize the website and for internal statistical purposes.
The aforementioned information will not be linked to or stored together with personal data.
Only in the event of an attack on our network infrastructure or in the case of suspected unauthorized or abusive use of one of the websites will the IP address be evaluated for investigative and defensive purposes and, if necessary, used in the context of criminal proceedings for identification as well as for civil and criminal measures against the users concerned.
We base the processing of data for these purposes on our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.
3.3 Contact form on the websites
In this context, we collect and process personal data only if users provide it voluntarily, e.g., via the contact form, email, or telephone. This data is processed exclusively for the purpose of responding to the respective inquiry.
The legal basis for this processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR and, where applicable, the performance of a contract (Art. 6 para. 1 lit. b GDPR). Users can object to this data processing at any time (see contact details above).
CSAG and CGSAG use a software application from Zoho Corporation GmbH, Trinkausstr. 7, 40213 Düsseldorf, Germany, to process contact requests submitted via a contact form. Therefore, your data may be stored in a Zoho Corporation database, which allows Zoho Corporation to access your data when necessary for providing the software and supporting its use. Information regarding data processing by third parties and any transfers abroad can be found further down in this privacy policy.
CPAG currently uses the WordPress backend of the CPAG website, operated by Agenza GmbH, Am Mattenhof 4a, 6010 Kriens, Switzerland, to process contact requests submitted via a contact form. Contact details submitted via the form are stored in the WordPress database and processed there for the purpose of responding to the request. Information on data processing by third parties and any transfers abroad can be found in section 2.11.
3.4 Cookies on the websites
To make visiting our websites more attractive and to enable the use of certain functions, we use cookies. Cookies are small text files that are stored on the user's device. Some of the installed cookies are automatically deleted after the browser session ends (session cookies). Other cookies remain on the user's device and allow us to recognize the browser on the next visit (persistent cookies).
We use cookies for various purposes that are necessary for the intended use of the websites, i.e., "technically necessary". Cookies are also used for security purposes, such as to prevent the unauthorized posting of content. Finally, we use cookies in the design and programming of our websites, for example, to enable the uploading of scripts or code.
The legal basis for this data processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in providing user-friendly and up-to-date websites.
Where legally required, we obtain the prior consent of users before placing cookies on their devices, such as tracking or marketing cookies. The legal basis for this data processing is Article 6(1)(a) GDPR.
We would like to inform users that certain cookies, which do not require prior consent, are already set as soon as users access the websites. However, users can configure their browser to notify them about the setting of cookies and decide individually whether to accept them, or to exclude the acceptance of cookies in certain cases or entirely. Refusing or disabling functional or technical cookies may limit the functionality of the websites.
Browsers offer users the option to control the storage of cookies on their respective devices. Descriptions for each browser can be found at the following links:
- Internet Explorer™: http://windows.microsoft.com/de-DE/windows-vista/Block-or-allow-cookies
- Safari™: https://support.apple.com/de-ch/guide/safari/ibrw850f6c51/mac
- Chrome™: http://support.google.com/chrome/bin/answer.py?hl=de&hlrm=en&answer=95647
- Firefox™: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
- Opera™: http://help.opera.com/Windows/10.20/de/cookies.html
3.5 Appointment booking via Calendly on the CSAG website
CSAG offers you the opportunity to schedule an appointment easily and conveniently. For this purpose, CSAG uses "Calendly". Calendly is a service of Calendly LLC, BB&T Tower, 271 17th St. NW, Atlanta, GA 30363.
When using Calendly, personal data such as your name, email address, and phone number, as well as any other information you provide when requesting an appointment, will be processed. This data is processed by Calendly. Use of this service is voluntary and based solely on your consent in accordance with Article 6(1)(a) of the GDPR.
When using the online appointment booking system, cookies from the provider Calendly are used. If you do not want your data to be processed by Calendly and transferred to the USA, please choose another way to book an appointment with us.
This privacy policy and Calendly's privacy policy apply to the use of Calendly and the associated data transfers. You can find them here: https://calendly.com/pages/privacyFurthermore, Calendly has under https://help.calendly.com/hc/en-us/articles/360007032633-GDPR-FAQs Further information on GDPR compliance has been published.
3.6 Use of Stripe as a payment service provider on the CSAG website
Payments made through the CSAG website are processed via the technical service provider Stripe. Payment processing is handled by the payment service provider Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
Only the data provided during the ordering process will be shared in accordance with Article 6 Paragraph 1 Letter b GDPR (name, address, account number, bank code, credit card number if applicable, invoice amount, currency, and transaction number). Your data will only be used for payment processing with the payment service provider Stripe Payments Europe Ltd. and only to the extent necessary. Further information on Stripe's data protection policy can be found at: https://stripe.com/gb/privacy.
3.7 Analysis Tools
For the purpose of tailoring our websites to user needs and continuously optimizing them, we use the web analytics services listed below. In this context, pseudonymized user profiles are created and cookies are used (see also section 3.4). The information generated by the cookie about your use of our websites is generally transmitted to a server of the service provider and stored and processed there together with the log data mentioned in section 3.2. This may also involve transmission to servers abroad, e.g., in the USA (for information on the lack of an adequate level of data protection and the proposed safeguards, see section 2.11).
Through data processing, we obtain, among other things, the following information:
- the navigation path that visitors follow on the website (including viewed content, selected or purchased products, or booked services);
- the time spent on websites or a specific page;
- the specific page from which the website is left;
- the country, region or city from which access is made;
- the end device (type, version, color depth, resolution, width and height of the browser window); and
- whether they are returning or new visitors.
The provider will use this information on our behalf to evaluate website usage, in particular to compile reports on website activity and to provide other services related to website and internet usage for market research purposes and to tailor the website to user needs. For these processing activities, we and the provider may, to a certain extent, be considered joint controllers within the meaning of data protection law.
The legal basis for this data processing with the following services is your consent within the meaning of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent or object to the processing at any time by rejecting or disabling the relevant cookies in your web browser settings (see section 3.4) or by using the service-specific options described below.
Regarding the further processing of data by the respective provider as the (sole) responsible party, including any transfer of this information to third parties (e.g., to authorities based on national legal regulations), we refer to the respective provider's privacy policy. In addition to the analytics services described in this section, certain technical infrastructure components used on the websites (see sections 3.7.3 and 3.7.4) may also transmit technical data related to the delivery of website content.
3.7.1 Google Analytics on the websites
We use the web analytics service Google Analytics from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, or Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (Google).
Contrary to the description in the general section above, IP addresses are not collected or stored in Google Analytics (in the version used here, "Google Analytics 4"). For access from the EU, IP address data is used only to derive location data and is then immediately deleted. When collecting measurement data in Google Analytics, all IP queries take place on servers located in the EU before the data traffic is forwarded to Analytics servers for processing. Google Analytics uses regional data centers. When connecting to the nearest available Google data center, the measurement data is sent to Analytics via an encrypted HTTPS connection. In these centers, the data is further encrypted before being forwarded to the Analytics processing servers and made available on the platform. The most suitable local data center is determined based on the IP addresses. This may also involve the transfer of data to servers abroad, e.g., in the USA (for information on the lack of an adequate level of data protection and the proposed safeguards, see section 2.11).
We also use the technical extension "Google Signals," which enables cross-device tracking. This makes it possible to link individual website visitors to different devices. However, this only happens if the visitor is logged into a Google service during their visit and has activated the "personalized advertising" option in their Google account settings. Even in these cases, we have no access to personal data or user profiles; they remain anonymous to us. If you do not wish to use "Google Signals," you can deactivate the "personalized advertising" option in your Google account settings.
Users can prevent the collection of data generated by the cookie and related to their use of the websites (including IP address) and the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en-GB.
Your personal data will be transferred to Google on the basis of our data processing agreement (in conjunction with Art. 28 GDPR / Art. 9 DSG).
3.7.2 Zoho PageSense on the CSAG website
CSAG uses Zoho PageSense, a service of Zoho Corporation, Trinkausstr. 7, 40213 Düsseldorf, Germany, to conduct A/B tests, heatmaps, and funnel analyses to improve the usability and performance of the CSAG website. PageSense uses cookies (see section 3.4) and processes usage data such as pages visited, click and scroll behavior, time spent on the site, device/browser information, and the displayed test variant, and generates aggregated reports.
Your personal data will be transferred to Zoho on the basis of CSAG's data processing agreement (in conjunction with Art. 28 GDPR / Art. 9 DSG). Further information on data processing by Zoho can be found at [link to Zoho's privacy policy] https://www.zoho.com/privacy-commitment.html.
3.7.3 JavaScript libraries via unpkg.com on the websites
The websites load JavaScript libraries via unpkg.com, a public Content Delivery Network. Requests to unpkg.com are routed through the infrastructure of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. When the websites access unpkg.com, technical data, including your IP address, browser information (user agent), the referring website URL, and the time of the request, may be transmitted to and processed by Cloudflare's servers. This processing is technically necessary to ensure the proper functionality of the websites.
The legal basis for this processing is our legitimate interest, pursuant to Article 6(1)(f) GDPR, in ensuring the technical functionality of the websites. Since Cloudflare is based in the USA, transfers of personal data are subject to Section 2.11 of this Privacy Policy. Cloudflare has implemented standard contractual clauses to ensure an adequate level of data protection. Further information on data processing by Cloudflare can be found at [link to Cloudflare's privacy policy] https://www.cloudflare.com/privacypolicy/.
3.7.4 Website translation via Linguise on the websites
The websites use Linguise, a translation service provided by Linguise by DXT ONE, 32565 B Golden Lantern St, Suite 191, Dana Point, CA 92629, USA, to offer content in multiple languages. When using the translation function, technical data, including your IP address, browser information (user agent), the referring website URL, and the time of the request, may be processed by Linguise.
The legal basis for this processing is our legitimate interest, pursuant to Article 6(1)(f) GDPR, in providing easily accessible, multilingual website content. Since Linguise is based in the USA, transfers of personal data are subject to Section 2.11 of this Privacy Policy. Further information on data processing by Linguise can be found at [link to Linguise's privacy policy] https://www.linguise.com/data-processing-agreement/.
3.8 Marketing Tools
We use services from various companies to present users with interesting online offers. This involves analyzing user behavior on our websites and on the websites of other providers in order to subsequently display individually tailored online advertising to users.
Most technologies for tracking user behavior and displaying targeted advertising use cookies (see also section 3.4), which allow the user's browser to be recognized across different websites. Depending on the provider, it may also be possible for users to be recognized online when using different devices (e.g., laptop and smartphone). This can occur, for example, when users access a service across multiple devices.
In addition to the data already mentioned that is collected when visiting websites (log data, see section 3.2) and the data collected through cookies (section 3.4), which may be transmitted to the companies involved in the advertising networks, the following data in particular is used to select the advertising that is potentially most relevant to you:
- Information about users that they have provided when registering for or using a service from advertising partners (e.g., gender, age group); and
- User behavior (e.g. search queries, interactions with advertising, type of websites visited, products or services viewed and purchased, newsletters subscribed to).
We and our service providers use this data to determine whether users belong to our target audience and take this into account when selecting advertisements. For example, users may see advertisements for products or services they viewed on other websites after visiting our website (retargeting). Depending on the amount of data, a user profile may also be created and automatically analyzed; advertisements are then selected based on the information stored in the profile, such as membership in certain demographic segments or potential interests or behaviors. This advertising may be displayed to users on various channels, including our websites or app (as part of on- and in-app marketing), as well as ad placements provided through online advertising networks we use, such as Google.
The data may subsequently be analyzed for billing purposes with the service provider and to evaluate the effectiveness of advertising measures in order to better understand the needs of our users and customers and to improve future campaigns. This may also include information indicating that the performance of an action (e.g., visiting certain areas of our websites or submitting information) can be attributed to a specific advertisement. We also receive aggregated reports from service providers on advertising activities and information about how users interact with our websites and advertisements.
The legal basis for this data processing is the consent of the users within the meaning of Art. 6 para. 1 lit. a GDPR. Users can withdraw their consent at any time by rejecting or disabling the relevant cookies in their web browser settings (see section 3.4). Further options for blocking advertising can also be found in the information provided by the respective provider, such as Google.
3.8.1 Google AdWords Conversion Tracking on Websites
We use Google Ads Conversion, a service provided by Google Ireland Limited, Google Building Gordon House, Barrow St, Dublin 4, Ireland, to advertise our attractive offers on external websites using Google Ads. The data from these advertising campaigns allows us to determine the success of individual advertising measures. In this way, we aim to display relevant advertising to users, make our websites more appealing to them, and ensure a fair calculation of advertising costs.
These advertisements are delivered by Google via so-called "ad servers." We use ad server cookies for this purpose, which allow us to measure certain parameters for success, such as ad display or user clicks. When users access our website via a Google ad, Google Ads stores a cookie on their device. This cookie typically stores the following data for analysis: the unique cookie ID, the number of ad impressions per campaign (frequency), the last impression (relevant for post-view conversions), and opt-out information (indicating that the individual no longer wishes to be targeted).
Cookies allow Google to recognize users' web browsers. If a user visits certain pages of an advertiser's website and the cookie stored on their computer has not expired, Google and the advertiser can recognize that the person clicked on the ad and was redirected to that page. Each AdSense customer is assigned a different cookie. Cookies cannot be tracked across advertisers' websites. We ourselves do not collect or process any personal data in connection with the aforementioned advertising measures. We only receive statistical analyses from Google. These analyses allow us to identify which of the advertising measures used are particularly effective. We do not receive any further data from the use of the advertising materials; in particular, we cannot identify users based on this information.
Due to the marketing tools used, users' browsers automatically establish a direct connection to Google's servers. We have no control over the scope and further use of the data collected by Google through these tools and therefore inform users to the best of our knowledge: By integrating Ads Conversion, Google receives information that users have accessed the relevant part of our website or clicked on one of our ads. If users are registered with a Google service, Google can associate the visit with their account. Even if users are not registered with Google or are not logged in, it is possible that the provider will learn and store their IP address.
Users can find more information about conversion tracking at https://support.google.com/google-ads/answer/1722022.
Users can prevent this tracking by refusing or disabling the setting of cookies in their browser (see section 3.4).
It cannot be completely ruled out that certain personal data may be transferred to servers abroad, e.g. in the USA (for the lack of an adequate level of data protection and the proposed safeguards, see section 2.11).
Your personal data will be transferred to Google on the basis of our data processing agreement (in conjunction with Art. 28 GDPR / Art. 9 DSG).
3.8.2 Google Tag Manager on the websites
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The Google Tag Manager is a tool that allows us to integrate tracking, analytics, and other technologies into our websites. The Google Tag Manager itself does not create user profiles, store cookies, or perform independent analyses. It merely serves to manage and deploy the tools integrated through it. However, the Google Tag Manager does collect your IP address, which may also be transferred to Google's parent company in the United States.
Details on data processing by Google can be found at https://policies.google.com/privacyGoogle may process personal data outside the EU/EEA.
We secure the transfer of personal data through standard contractual clauses (see section 2.11).
Your personal data will be transferred to Google on the basis of our data processing agreements (in conjunction with Art. 28 GDPR / Art. 9 DSG).
3.8.3 Affiliate Program and Partner Tracking
Cereneo collaborates with selected partners and distributors. If you access our website via an individual affiliate link, we store information that allows us to associate your visit with the respective partner. For this purpose, we process, in particular, the affiliate or partner identification, the time of the visit, the pages viewed, and any information submitted as part of an inquiry or booking. This association is made via URL parameters and technical tracking mechanisms (e.g., session or cookie technologies).
This processing serves to measure the success of our affiliate partners, to attribute inquiries and bookings, to calculate partner commissions, and to analyze and optimize our sales and marketing activities. As part of affiliate tracking, a cookie with an anonymous partner identifier may be stored on your device; the maximum storage period is 90 days. Affiliate data is stored only as long as necessary for the aforementioned purposes or as required by law.
The legal basis for this processing is our legitimate interest, pursuant to Article 6(1)(f) GDPR, in the implementation and optimization of our partner program. Insofar as the affiliate cookie is not technically necessary, we obtain your prior consent in accordance with Article 6(1)(a) GDPR (see section 3.4).
If affiliate partners are located outside of Switzerland or the EEA, section 2.11 applies.
3.8.4 Zoho Marketing Automation on the CSAG website
CSAG uses Zoho Marketing Automation. The provider is Zoho Corporation GmbH, Trinkausstr. 7, 40213 Düsseldorf, Germany. Zoho Marketing Automation is a tool that allows CSAG to manage campaigns and mailing lists and to evaluate the effectiveness of CSAG's online marketing. For this purpose, Zoho can process contact data, campaign metadata, and website interaction data collected via cookies (see section 3.4).
Your personal data will be transferred to Zoho on the basis of CSAG's data processing agreement (in conjunction with Art. 28 GDPR / Art. 9 DSG). Further information on data processing by Zoho can be found at [link to Zoho's privacy policy] https://www.zoho.com/privacy-commitment.html.
3.9 YouTube on the websites
The websites embed videos from YouTube, a service of Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in enhanced privacy mode. According to YouTube, this mode prevents YouTube from storing information about visitors before they watch a video. However, data transfers to YouTube's partner networks, including Google DoubleClick, can still occur regardless of whether a video is played.
As soon as a user starts a YouTube video, a connection is established to YouTube's servers, which may include information about the visited page. If the user is logged into their YouTube account at that time, YouTube can associate this activity with their personal profile. Users can prevent this by logging out of their YouTube account before using the website.
YouTube may also store cookies or use similar recognition technologies (e.g., device fingerprinting) on users' devices. This information may be used for video statistics, to improve the user experience, and for fraud prevention. After a video starts playing, further data processing operations may be triggered that are outside of our control.
The legal basis for embedding YouTube videos is our legitimate interest in providing informative content to website visitors (Art. 6 para. 1 lit. f GDPR). Where consent is required, it will be obtained separately and can be withdrawn at any time. Further information on data processing by Google can be found at [link to Google's privacy policy] https://policies.google.com/privacy.
3.10 Google Maps on the websites
These websites use Google Maps, a map service provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Maps allows us to display interactive map content and provide website users with convenient geographical orientation and directions to our locations.
When users access a page that includes Google Maps, a connection to Google's servers is automatically established. Google then receives information about which websites the users have visited and can process other technical data, such as the users' IP address, browser information, device settings, location data (if enabled on the device), and interaction data with the embedded map. If users are logged into their Google account, Google can directly associate this information with their personal profile. Users can prevent this association by logging out of their Google account before accessing the map.
In connection with the provision of Google Maps, Google may store cookies or use similar tracking technologies (e.g., device fingerprinting) on users' devices. These technologies may be used, among other things, to ensure the correct display of map content, to guarantee the security and functionality of the service, and to analyze service usage for optimization and personalization purposes. After the Google Maps content has fully loaded, further data processing operations may be triggered that are outside our control.
The use of Google Maps is based on our legitimate interest, as defined in Article 6(1)(f) GDPR, in presenting our locations in an appealing and user-friendly manner and facilitating navigation for website users. Further information about Google Maps can be found at [link to Google Maps information] https://policies.google.com/privacy?hl=en.
3.11 Social Media on the Websites
The websites contain links to profiles on the social networks of the following providers:
- Meta, operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, https://www.facebook.com/privacy/policy/;
- LinkedIn, operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, https://www.linkedin.com/legal/privacy-policy;
- WhatsApp, operated by WhatsApp Ireland Limited, Merrion Road, Dublin, Ireland https://www.whatsapp.com/legal/privacy-policy-eea;
- YouTube, operated by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland, https://policies.google.com/privacy?hl=en.
Sharing functions (plugins) are deactivated by default, so no data is sent to social networks simply by accessing the website. We have integrated the plugins in such a way that a connection to the social network servers is not automatically established. A connection is only established when a user actively clicks on a profile link or a share button, thereby consenting to the transmission and further processing of data by the respective provider.
When a user clicks on a social media element, their browser establishes a direct connection to the servers of the respective network. The network receives information about the visited page and the user's IP address. This information is immediately transmitted to a server of the provider and stored there. Data may be transferred to servers in the USA; section 2.11 applies. We have no control over the scope of data that the providers collect through these interactions.
If the user is logged into their social media account at the time of clicking, the network can immediately associate this activity with their profile. To prevent this, users should log out of their account before interacting with a social media element on the website.
When users interact with a share button, the corresponding information is transmitted to the provider's servers. Content shared by the user (e.g., expressing interest in a product or service) can be published on the social network and displayed to other users. The provider can use this information for advertising and personalization purposes, including creating usage, interest, and relationship profiles, evaluating browsing behavior on websites in relation to advertising displayed on the social network, and providing other services related to network usage. For details on the scope of data collection, further processing, and user rights, please refer to the privacy policies of the respective providers.
The legal basis for the profile links is our legitimate interest, as defined in Article 6(1)(f) GDPR, in maintaining and promoting our social media presence. The legal basis for the sharing functions is consent, as defined in Article 6(1)(a) GDPR. Users can withdraw their consent at any time in accordance with the instructions of the respective provider.
3.12 Providers in connection with the websites
An overview of all third-party providers whose services are used in connection with the websites can be found in the list of third-party recipients in section 2.9.
4. Specific data processing CSAG
Unless expressly stated otherwise in this section, the information in section 2 remains unchanged.
4.1 Medical and therapeutic treatment (including offer management and patient onboarding)
CSAG may process the following categories of personal data of patients and, where applicable, their accompanying persons and/or representatives:
- Personal data that patients or their representatives provide to CSAG as part of the service, upon admission or registration (e.g., personal data, medical reports of previous treatments, medical conditions, medical records, contact details of the contact person; lead source; patient's wishes; possible entry and exit dates, reference; visa information, insurance information; religion; treating physician (including contact address));
- Personal data that CSAG receives from third parties with the consent of the patient (e.g. travel and accommodation information, medical records and medical documents of third-party service providers involved; laboratory test reports);
- Financial data that CSAG has prepared for the offer (estimated data), such as expected revenue, possible entry and exit dates, planned monthly amount, probability of success; or
- Personal data collected during treatment (e.g., medical conditions, prescribed therapies and treatment results, diagnostic/assessment/image material, reports, recording of training progress, as well as the discharge report and billing information).
With the patient's consent, CSAG may arrange medical examinations with third-party specialists. For this purpose, CSAG may provide these specialists with the information necessary for such an examination, such as the patient's contact details, medical reports, etc.
With the patient's consent, CSAG may commission third parties to provide certain services, such as transportation. For this purpose, CSAG may share the information necessary for these third parties to provide the requested services.
CSAG may use third-party tools, devices, and applications for diagnostic, therapeutic, and monitoring purposes. These include, but are not limited to, devices and systems for neurological assessment and stimulation (e.g., EEG, EMG, evoked potentials, tDCS/tES, vagus nerve stimulation), movement and rehabilitation therapy (e.g., robotic therapy systems, functional electrical stimulation, exoskeletons, treadmill and balance systems), cardiorespiratory and sleep monitoring (e.g., ECG/Holter, polysomnography, pulse oximetry, CPAP monitoring, blood pressure monitoring), imaging and radiology (e.g., MRI/PACS, teleradiology), infusion and medication systems, and digital therapy applications.
For these purposes, the following categories of personal data are typically entered and processed: name, date of birth, weight and height, as well as data on therapy progress and clinical measurements. The providers of these tools and applications may independently collect and process further data in connection with their use. CSAG is only responsible for the careful selection of such tools and for the clinical activities over which CSAG has direct influence.
For billing purposes, CSAG processes the contact details, billing address and invoice amount of the patients.
The legal basis for this data processing is the preparation and/or fulfillment of the contract (Art. 6 para. 1 lit. b GDPR), exceptionally the legitimate interest of CSAG (Art. 6 para. 1 lit. f GDPR) and, where applicable, the consent of the patients given in the registration form or in the specific individual case.
4.2 Data exchange with the Lake Lucerne Institute
For the purpose of further developing and improving therapeutic approaches, as well as monitoring, measuring, and evaluating rehabilitation progress, CSAG collaborates with Lake Lucerne Institute AG (LLUI), a non-profit public limited company founded in 2021 under Swiss law. The patient is primarily cared for by CSAG staff. For the aforementioned purposes, particularly sensitive personal data of the patient (e.g., measurements concerning the development of the musculoskeletal system) is collected, even after the patient's hospital stay. CSAG or LLUI staff may contact the patient for this purpose.
CSAG grants LLUI access to patient records in order to process the personal data contained therein for the aforementioned purposes. Data collected from or about the patient in connection with these purposes will be stored on CSAG servers. CSAG ensures that LLUI processes the particularly sensitive personal data collected from or about the patient (including data in the patient record) only as permitted by CSAG under this privacy policy and applicable law.
For the aforementioned purposes, CSAG and LLUI may suggest the use of third-party (software) applications – including mobile applications (e.g., teletherapy applications that use smartphone measurements to compile patient data and transmit it to CSAG, or applications that facilitate communication between CSAG or LLUI and the patient and assist with scheduling appointments). The final decision regarding the use of such applications rests with the patient. CSAG is not responsible for the collection and processing of personal data by such applications. Responsibility lies with the provider of the respective application. It is the patient's responsibility to obtain the necessary information about data processing by such applications.
5. Specific data processing CGSAG
5.1 Teletherapy and home services
Unless otherwise agreed with the patient or their representative, teletherapy and home-based services are provided by CGSAG, a company of the Neuro Recovery Group, on the basis of an independent contractual relationship with the patient or their representative. Personal data of patients treated by CSAG who, after discharge from CSAG's inpatient facility, decide to continue treatment via teletherapy and/or home-based services, will be transferred by CSAG to CGSAG to the extent that this personal data is necessary for the continuation of treatment, including the personal data specified in Section 4.1 of this Privacy Policy.
In connection with teletherapy services, CGSAG primarily uses Microsoft Teams, a service provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Dublin 18, Ireland (part of Microsoft Corporation). Personal data transmitted during teletherapy sessions (including name, image, voice, and session content) may be processed by Microsoft. Data may be transferred to Microsoft's global infrastructure, including servers outside the EU/EEA; in this case, Section 2.11 applies. Microsoft has implemented Standard Contractual Clauses to ensure an adequate level of data protection. Further information on data processing by Microsoft can be found at https://privacy.microsoft.com.
The legal basis for this data processing is the preparation and/or fulfillment of the contract (Art. 6 para. 1 lit. b GDPR), exceptionally the legitimate interest of CGSAG (Art. 6 para. 1 lit. f GDPR) and, where applicable, the consent of the patients given in the registration form or in the specific individual case.
5.2 Consulting services
CGSAG can offer consulting services, e.g. the installation of devices in a patient's home.
CGSAG may process personal data for the purpose of providing such consulting services, including identification data (e.g., name, first name, postal address). The legal basis for data processing is the preparation and/or performance of the contract (Art. 6 para. 1 lit. b GDPR) to which the data subject is a party.
6. Specific data processing CPAG
CPAG provides (i) prevention/longevity/health services (including medical and therapeutic services where applicable) and (ii) hospitality services (e.g. accommodation, restaurant service, health and lifestyle services, gym and spa services and other hotel-like services).
6.1 Prevention and therapeutic services (preventive/outpatient)
CPAG provides prevention, longevity, and health-oriented services designed to support clients in maintaining or improving their well-being, lifestyle, and overall health. These services include, but are not limited to, preventive assessments, lifestyle analyses, personalized prevention programs, longevity consultations, nutritional advice, sleep and recovery support, stress management activities, and exercise and training programs.
In addition to preventative services, CPAG can provide therapeutic services in the fields of neurology and general health. These services include, among other things, medical consultations and comprehensive medical diagnostics.
In connection with the provision of these services, CPAG processes the following categories of personal data of customers and, where applicable, their accompanying persons and/or representatives:
- Personal data that customers or their representatives provide to CPAG as part of the offer, upon entry or registration (e.g. personal data, reports of previous treatments, medical records, contact details of the contact person; lead source; wishes of the customer; possible entry and exit dates, reference; visa information, insurance information; religion; treating physician (including contact address));
- Personal data that CPAG receives from third parties with the consent of the customer (e.g. travel and accommodation information, medical records and documents of third-party service providers involved; laboratory test reports);
- Financial data that CPAG has prepared for the offer (estimated data), such as expected revenue, possible entry and exit dates, planned monthly amount, probability of success; or
- Personal data collected during the provision of services (e.g. prescribed treatments and treatment results, diagnostic/assessment/image material, reports, recording of training progress, as well as the discharge report and billing).
With the client's consent, CPAG may arrange services and/or medical examinations with third-party specialists. For this purpose, CPAG may provide these specialists with the information necessary for such a service or examination, such as the client's contact details, treatment records, medical reports, etc.
CPAG may use third-party tools and applications for the treatment of clients. For these purposes, the following categories of personal data are typically entered and processed: client's name, date of birth, weight, and height. Data on training and treatment progress is also collected and processed. The providers of these tools and applications may collect and process additional data about the use of their tools and applications.
Furthermore, with the customer's consent, CPAG may engage third parties to provide certain services, such as transportation. For this purpose, CPAG may share the information necessary for these third parties to provide the requested services.
For billing purposes, CPAG processes the contact details, billing address and invoice amount of the customers.
The legal basis for this data processing is the preparation and/or fulfillment of the contract (Art. 6 para. 1 lit. b GDPR), exceptionally the legitimate interest of CPAG (Art. 6 para. 1 lit. f GDPR) and, where applicable, the consent given by customers in the registration form or in the specific individual case.
6.2 Hospitality services (accommodation, restaurant, gym & spa, guest services)
CPAG processes personal data for the purpose of providing hospitality services, including accommodation, catering, access to gym and spa facilities, and related guest services. The categories of personal data processed include identification data (e.g., title, first name, last name, email address, telephone number), financial information (e.g., bank account information, payment method), reservation and booking details (e.g., room type, length of stay, number of guests, arrival and departure times), and any preferences or special requests communicated by the customer (e.g., dietary requirements, accessibility needs, room preferences).
The legal basis for this data processing is the performance of the contract (Art. 6 para. 1 lit. b GDPR) in which the customer is involved. Insofar as additional preferences are voluntarily specified and are not required for the provision of the booked services, the legal basis is the customer's consent pursuant to Art. 6 para. 1 lit. a GDPR.
For property management, reservation processing, and payment processing related to accommodation and other CPAG services, CPAG uses MEWS from Mews Systems BV, Vijzelstraat 68, 1017 HL Amsterdam, Netherlands. Further information on data processing by Mews Systems BV can be found at [link to Mews Systems BV's privacy policy] https://www.mews.com/en/privacy-policy.
CPAG uses OpenTable, a service provided by OpenTable, Inc., 1 Montgomery Street, Suite 700, San Francisco, CA 94104, USA, to manage restaurant reservations. Personal data processed includes name, email address, telephone number, number of people in the party, and any special requests. Because OpenTable is based in the USA, transfers of personal data are subject to Section 2.11 of this Privacy Policy. OpenTable has implemented Standard Contractual Clauses to ensure an adequate level of data protection. Further information: https://www.opentable.com/legal/privacy-policy.
For payment processing at the restaurant point of sale, CPAG uses Worldline, a payment service provided by Worldline AG, Hardturmstrasse 201, 8005 Zurich, Switzerland. Personal data processed in this context includes payment card details and transaction information, which are processed solely for the purpose of completing the payment transaction. Further information on data processing by Worldline can be found at [link to Worldline's privacy policy] https://worldline.com/en/compliancy/privacy.
6.3 CERENEO PREVENTION App
CPAG operates the CERENEO PREVENTION application ("App") and is the data controller responsible for the personal data collected and processed via the App. CPAG processes such data in accordance with this Privacy Policy and applicable data protection law, including, where relevant, the Swiss Telecommunications Act (TKG).
Within the app, we enable you to use and view the following information in particular:
- Unified Health Dashboard: A central overview of health, lifestyle and longevity data on one platform.
- Wearable integration: Synchronization with devices such as Apple Watch, Fitbit, Oura and other trackers to collect real-time data (activity, sleep, stress, etc.).
- Personalized health goals: Daily goals and recommendations based on individual health data.
- Nutrition and meal tracking: Meal tracking (including photo-based tracking) with automated nutritional analysis.
- Appointment management: Book, reschedule or cancel appointments directly in the app.
- Secure news: Encrypted chat function for communication with healthcare professionals.
- Digital forms and documentation: Access and complete medical forms and required documents in the app.
The following subsections describe the specific data processing activities related to individual app functions and the third-party services integrated into the app. You can access this privacy policy at any time within the app via: Home screen > Hamburger menu > About & Settings > About > Privacy Policy.
6.3.1 Downloading and accessing the app
When you download the app, the respective app store provider (e.g., Apple App Store / Google Play) processes personal data such as your account ID, the time of download, and device identifiers. The app store provider acts as an independent data controller in this respect. We have no influence over their data processing. Please refer to their respective privacy policies
- Google Play Store (Android): Google LLC., 1600 Amphitheater Parkway, Mountain View, California 94043, USA: https://policies.google.com/privacy?hl=en&gl=de
- App Store (iOS): Apple Inc., One Apple Park Way, Cupertino, California, USA, 95014: https://www.apple.com/legal/privacy
6.3.2 App Permissions
To enable the app's core functions, it may request access permissions such as Bluetooth, location services, and notifications. If you grant such permissions, you can revoke them at any time in your mobile device's settings. Revoking permissions required for a function may prevent that function from working correctly.
6.3.3 Push notifications / Token data
When you enable push notifications, your mobile device's operating system generates a unique notification token (e.g., Apple Push Notification Service / Google Firebase Cloud Messaging), which is processed to deliver notifications to your mobile device. We use this token to deliver (i) service/technical notifications (e.g., firmware, battery, or feature updates) and, if you have consented, (ii) marketing notifications. You can disable push notifications at any time in your mobile device's settings and/or within the app.
6.3.4 Cookies
Cookies contribute in many ways to making the use of our app easier, more enjoyable, and more meaningful. Cookies are information files that your web browser automatically saves to your device's hard drive when you visit our app. We use, in particular, technically necessary cookies, performance cookies, and functional cookies.
We use these cookies, for example, to temporarily save your entries when filling out a form in the app, so you don't have to re-enter the information when visiting another page. Cookies can also be used to identify you as an authorized and registered user after you've registered in the app, without requiring you to log in again when visiting another page.
Cookies are usually accepted automatically. However, you can disable this function so that no cookies are stored on your device or a message always appears when you receive a new cookie. Disabling cookies may prevent you from using all the features of our app.
6.3.5 Tracking
We may use tracking tools to tailor our app to your needs and continuously optimize it. In this context, pseudonymized user profiles are created and small text files ("cookies") stored on your device are used. The information generated by the cookies about your use of our app is transmitted to the servers of the provider of these services, stored there, and processed on our behalf. We may also receive the following information:
- the navigation path of a user,
- the time spent in the app,
- the country, region or city from which access is made,
- the device (type, version, color depth, resolution, width and height of the browser window), and
- whether it is a returning or new user.
The information is used to evaluate app usage, generate reports on app activity, and provide other services related to app and internet usage for market research and to tailor the app to user needs. Furthermore, this information may be transferred to third parties if required by law or if third parties process this data on our behalf.
The legal basis for this data processing is your consent in accordance with Article 6(1)(a) GDPR. You can withdraw your consent at any time in the app settings.
6.3.6 Google Maps
CPAG uses Google Maps for location-based functions within the app. The provisions of section 3.10 of this privacy policy apply accordingly.
6.3.7 Scheduling appointments via Calendly
CPAG uses Calendly, a service of Calendly LLC, BB&T Tower, 271 17th St. NW, Atlanta, GA 30363, USA, to schedule onboarding calls and appointments related to the app. Personal data such as name, email address, and phone number are processed by Calendly when you book an appointment. Because Calendly is based in the USA, transfers of personal data are subject to Section 2.11 of this Privacy Policy. For more information: https://calendly.com/pages/privacy.
6.3.8 Delivery of one-time passwords via Twilio
CPAG uses Twilio, a service of Twilio Ireland Limited, 70 Sir John Rogerson's Quay, Dublin 2, D02 R296, Ireland, to deliver one-time passwords (OTPs) used for authentication within the app. The personal data processed includes your phone number and the OTP. The legal basis for this processing is the performance of a contract (Art. 6 para. 1 lit. b GDPR). Further information on data processing by Twilio can be found at https://www.twilio.com/en-us/legal/privacy.
6.3.9 Video consultations via Zoom
For video consultations conducted via the app, CPAG uses Zoom, a service of Zoom Video Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. Personal data transmitted during video sessions (including name, image, voice, and session content) may be processed by Zoom. Because Zoom is based in the USA, transfers of personal data are subject to Section 2.11 of this Privacy Policy. Zoom has implemented standard contractual clauses to ensure an adequate level of data protection. Further information: https://explore.zoom.us/en/privacy.
Last modified in July 2026