privacy policy
1. Data controller and contact
The data controller responsible for data processing on this website under the General Data Protection Regulation (GDPR) is:
LT Laserazor Treatment GmbH
represented by Managing Director Mithat Arda
Straße der Jugend 18, 14974 Ludwigsfelde
Germany
Commercial register: Amtsgericht Potsdam, HRB 37070 P
VAT ID: DE356621370
E-Mail: [email protected]
For privacy-related enquiries, you can reach us at:
[email protected]
2. Data protection officer
According to current assessments, appointing a data protection officer is not mandatory under § 38 BDSG in conjunction with Art. 37 GDPR, as there is no extensive processing of special categories of personal data (Art. 9 GDPR) as a core activity using automated means — health and medical history data are kept exclusively locally and in paper form in the respective branch (see section 8). Please direct any data protection enquiries to the contact details mentioned in section 1.
3. General principles of data processing
We process personal data exclusively within the framework of legal requirements (DSGVO, BDSG, TTDSG). In this privacy policy, we provide transparent information about the nature, scope, and purpose of the processing, as well as your rights.
Legal basis for processing (Art. 6 GDPR):
- Art. 6 Para. 1 lit. a GDPR — Consent (e.g. cookie consent, marketing)
- Art. 6 Para. 1 lit. b GDPR — Performance of a contract / pre-contractual measures (booking, treatment)
- Art. 6 Para. 1 lit. c GDPR — Legal obligation (e.g. retention periods, NiSV documentation)
- Art. 6 para. 1 lit. f GDPR — legitimate interest (IT security, fraud prevention)
- Art. 9 para. 2 lit. a GDPR — explicit consent to process special categories (health data in the medical history form)
For setting or reading cookies or similar technologies that are not strictly necessary, § 25 Abs. 1 TTDSG in conjunction with Art. 6 Abs. 1 lit. a DSGVO forms the legal basis.
4. Hosting, Content Delivery Network and server log files
4.1 Hosting (Hetzner)
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located in data centres within the European Union. A data processing agreement is in place with Hetzner in accordance with Art. 28 GDPR.
4.2 Content Delivery Network / security (Cloudflare)
To deliver the website, prevent DDoS attacks and manage DNS, we use services from Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, represented in Europe by Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 München.
Cloudflare acts as an intermediary proxy between your browser and our servers. This involves processing, among other things, your IP address, time of visit, browser/device used and technical connection data to speed up page delivery and prevent attacks.
Legal basis: Art. 6 Para. 1 lit. f GDPR (legitimate interest in IT security, performance, availability). A data processing agreement is in place with Cloudflare in accordance with Art. 28 GDPR, alongside EU standard contractual clauses (Art. 46 Para. 2 lit. c GDPR). Cloudflare is certified under the EU-US Data Privacy Framework, which recognises an adequate level of protection in accordance with Art. 45 GDPR. Further information: cloudflare.com/privacypolicy.
4.3 Server log files
When you visit the website, your browser transmits technically necessary information that is automatically recorded in server log files:
- IP address of the requesting device
- Date and time of access
- Name and URL of the accessed file
- Referrer URL (previously visited website)
- Browser used, operating system, language
- Data volume transferred, HTTP status code
Legal basis: Art. 6 Para. 1 lit. f GDPR (legitimate interest in IT security, abuse prevention, statistics). The log files are automatically deleted after 14 days at the latest, unless specific evidence of a security incident justifies longer retention.
5. SSL/TLS encryption
This site uses SSL/TLS encryption for security reasons and to protect confidential content. You can recognise an encrypted connection by the "https://" in the address bar and the padlock icon in your browser.
6. Cookies & similar technologies
Our website uses cookies (text files) and similar technologies (LocalStorage, SessionStorage, pixels). We distinguish between:
- Technically necessary cookies — required to run the website (e.g. language and consent settings). Legal basis: § 25 Abs. 2 Nr. 2 TTDSG, Art. 6 Abs. 1 lit. f GDPR. No consent required.
- Statistics/analytics cookies — measure website usage. Only with your consent. Legal basis: § 25 Abs. 1 TTDSG, Art. 6 Abs. 1 lit. a GDPR.
- Marketing/tracking cookies — enable personalised retargeting. Only with consent. Legal basis: Sec. 25 Para. 1 TTDSG, Art. 6 Para. 1 lit. a GDPR.
You can adjust your cookie settings or withdraw your consent at any time via the cookie banner (accessible via the "Cookie settings" link in the footer). Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
7. Use of third-party services
Below, we provide information about all third-party services used on the website.
7.1 Google Tag Manager
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Parent company: Google LLC, USA).
Purpose: Technical management of marketing and analytics tags. GTM itself does not set tracking cookies, but loads additional tags.
Data: IP address, device identifiers.
Legal basis: Art. 6(1)(a) GDPR (consent).
Third country: USA; Guarantees: EU standard contractual clauses, EU-US Data Privacy Framework (DPF-certified).
Withdrawal: via the cookie banner.
7.2 Google Analytics 4
Provider: Google Ireland Limited, Dublin (Parent company: Google LLC, USA).
Purpose: Reach measurement, anonymised analysis of user behaviour.
Data: truncated IP address (IP anonymisation active), device/browser, visited pages, time on site, pseudonymous client ID.
Storage duration: up to 14 months.
Legal basis: Art. 6(1)(a) GDPR.
Third country: USA; Guarantees: EU standard contractual clauses, DPF-certified.
Withdrawal: Cookie banner or browser add-on at tools.google.com/dlpage/gaoptout.
7.3 Meta Pixel (Facebook / Instagram)
Provider: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (Parent company: Meta Platforms, Inc., USA).
Purpose: Conversion measurement, creation of target groups ('Custom Audiences') for ads on Facebook & Instagram.
Data: IP address, browser/device ID, visited pages, events (e.g. 'Trial session booked'), where applicable Facebook login status.
Storage duration: up to 2 years.
Legal basis: Art. 6(1)(a) GDPR.
Third country: USA; Guarantees: EU standard contractual clauses, DPF-certified.
Joint controllership: For certain processing steps, there is joint controllership with Meta under Art. 26 GDPR based on Meta's 'Controller Addendum'.
Withdrawal: Cookie banner and ad settings at facebook.com/settings?tab=ads.
7.4 Phorest (online appointment booking)
Provider: Phorest Salon Software Ltd., 14 Fitzwilliam Place, Dublin 2, D02 YV82, Ireland.
Purpose: Online appointment booking and management of customer master data for bookings.
Data collected during the online booking process: strictly name, mobile number and E-Mail address as well as the selected appointment, location and treatment zone.
No health or medical history data is collected via the online booking process. This is recorded exclusively on-site at the studio during the personal consultation and medical history interview (see section 8).
Legal basis: Art. 6(1)(b) GDPR (contract initiation/performance).
Server location: European Union. A data processing agreement is in place with Phorest in accordance with Art. 28 GDPR.
Further information: phorest.com/de/datenschutz.
7.5 Google Fonts (hosted locally)
We embed the fonts used locally on our server; there is no connection to Google servers when the page is loaded. In this respect, no personal data is transferred to Google.
7.6 Social media profiles (links only)
You'll find links to our profiles on Facebook, Instagram, TikTok and WhatsApp on our website. Data is transferred to the respective platforms only after you click on the corresponding icons. Simply loading our website does not transfer any data to the platforms (known as the "two-click solution"/plain link).
7.7 Google Maps
We embed interactive maps from Google Maps on our location pages. Provider: Google Ireland Limited, Dublin. When you load the map, your IP address and technical information, among other things, are transferred to Google.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent via cookie banner).
Third country: USA; Guarantees: EU standard contractual clauses, DPF-certified.
8. Processing as part of the treatment
As part of initiating and fulfilling the contract, we process the following data:
8.1 Online (Website / Phorest booking)
- Master/contact data: Name, mobile number, E-Mail address
- Booking details: chosen appointment, location, treatment area
Legal basis: Art. 6 Para. 1 lit. b GDPR (contract initiation). Stored on EU servers at Phorest (see section 7.4).
8.2 On-site at the studio (strictly physical/local)
- Health and medical history data (special category under Art. 9 GDPR): Fitzpatrick skin type, medication, allergies, relevant pre-existing conditions, pregnancy, tattoos in the treatment area, tanning status
- Consultation and consent documentation according to NiSV
- Treatment documentation: completed sessions, device parameters, observations
- if applicable, additional master data (address, date of birth, signature)
- Payment details: receipts, invoices; card payments are processed by an external payment provider, meaning we don't receive your card details
Important note on the storage of health data: Health and medical history data are kept exclusively in paper form at the respective studio in lockable cabinets. Processing in cloud systems or transmission to external providers does not take place. Only the staff responsible for your treatment, who are subject to professional confidentiality obligations, have access.
Legal basis:
- Art. 6 Para. 1 lit. b GDPR (Performance of a contract)
- Art. 6 Para. 1 lit. c GDPR in conjunction with Sec. 5 NiSV (legal obligation to document)
- Art. 9 para. 2 lit. a GDPR (explicit written consent to process special categories)
Retention period:
- Treatment and medical history documentation: 10 years (analogous to § 10 MBO-Ä, NiSV documentation requirement)
- Tax-relevant documents (invoices): 8–10 years in accordance with §§ 147 AO, 257 HGB
- Other contract details: up to 4 years after the end of the contract
- Online booking data (Phorest): deleted upon request or at the latest 3 years after your last booking
9. Contact via E-Mail, phone or WhatsApp
When you get in touch, we process your details (name, contact info, request) to handle your enquiry.
Legal basis: Art. 6 Para. 1 lit. b GDPR (contract initiation) or Art. 6 Para. 1 lit. f GDPR (legitimate interest in efficient communication).
The data is deleted as soon as its purpose has been fulfilled and there are no legal retention requirements.
Note on WhatsApp: When contacting us via WhatsApp (Meta Platforms Ireland Ltd.), your phone number and message content are processed by the service provider. We recommend not sending sensitive health information via WhatsApp; please use a personal consultation in the studio for this.
10. Trial session abuse prevention
To verify your new customer status for the free trial session, we cross-check your name, E-Mail, mobile number and, if applicable, your IP address with existing booking and customer records.
Legal basis: Art. 6 Para. 1 lit. f GDPR (legitimate interest in preventing misuse). The verification data will be deleted after a maximum of 12 months, provided no booking was made.
11. Disclosure to recipients
Your data will only be passed on to the following categories of recipients and only to the extent necessary:
- Data processors: IT hosting (Hetzner), CDN/security (Cloudflare), booking system (Phorest), analytics/marketing (Google, Meta) — each based on data processing agreements according to Art. 28 GDPR
- Payment provider: for card, SEPA or other payments
- Tax consultancy and auditing: to fulfil legal obligations
- Authorities and courts: only within the scope of legal obligations
Health and medical history data are generally not passed on to third parties (exception: legal obligation or explicit consent).
12. Transfers to third countries
When using services from US providers (Google Analytics, Google Tag Manager, Google Maps, Meta Pixel, Cloudflare), personal data may be transferred to the US. The legality is based on:
- EU standard contractual clauses in accordance with Art. 46 para. 2 lit. c GDPR
- the adequacy decision of the EU Commission of 10. July 2023 on the EU-US Data Privacy Framework (DPF) — all mentioned providers are DPF-certified, which recognises an adequate level of protection in accordance with Art. 45 GDPR
Certifications can be viewed at dataprivacyframework.gov.
Despite these guarantees, access by US authorities under local law cannot be completely ruled out. By giving your consent in the cookie banner, you expressly agree to these transfers (Art. 49 Para. 1 lit. a GDPR, alternatively).
13. Automated decision-making / profiling
Exclusively automated decision-making, including profiling, with legal effect according to Art. 22 GDPR does not take place.
13a. Use of AI systems
We use artificial intelligence systems for some of our imagery and to draft editorial texts. AI-generated images are marked with "AI-generated" directly on the image and in the alt text (Art. 50 of Regulation (EU) 2024/1689 — AI Act). You can find details in the AI transparency notice.
In this process, no personal data from website visitors or clients is transmitted to AI systems. In particular, your medical history, photos, contact details and booking data are not used for training or operating AI models. There is no biometric identification, emotion recognition or automated categorisation of individuals using AI.
14. Your rights as a data subject
You have the following rights under the GDPR:
- Access to processed data (Art. 15 GDPR)
- Rectification of incorrect data (Art. 16 GDPR)
- Erasure ("right to be forgotten", Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests, particularly direct marketing (Art. 21 GDPR)
- Withdrawal of consent with future effect (Art. 7 Para. 3 GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR)
To exercise your rights, simply send an informal message to [email protected] or by post to the address mentioned in section 1. We will process your request immediately, and at the latest within one month (Art. 12 Para. 3 GDPR).
15. Competent supervisory authority
The data protection supervisory authority responsible for us is:
The State Commissioner for Data Protection and the Right to Inspect Files Brandenburg
Stahnsdorfer Damm 77, 14532 Kleinmachnow
Tel.: +49 33203 356‑0
www.lda.brandenburg.de
Depending on where you live or work, you can also contact your local supervisory authority.
16. Obligation to provide data
To conclude a treatment contract, the data mentioned in section 8 is required. Without this information, we cannot offer the contract or carry out the treatment safely. Any further details (e.g. newsletter sign-up, marketing consent) are provided voluntarily.
17. Changes to this privacy policy
We update this privacy policy promptly in the event of changes to our processing operations, new tools or changed legal requirements. The current version is always available at this URL; the status stated above is authoritative.