Privacy Policy
Rebuilt for the STRATO migration and the actual functions of this website.
1. Privacy at a glance
General information
This website processes personal data when you access the website, contact us, send a care request or §37.3 consultation request, check the service area or submit a job application. Personal data is information that can be linked to an identifiable person.
The public website is expressly not designed as a patient record or care-documentation system. Diagnoses, medical reports, medication plans and medical documents are not requested through the designated website forms.
2. Controller
Dream Team APD GmbH
Stadtplatz 2b, 84529 Tittmoning
Germany
Phone: 086838919851
Email: contact@dreamteam-pflegedienst.de
3. Hosting with STRATO
As part of the migration, the website is operated with STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. When the website is accessed, technically necessary connection and server data may be processed, in particular IP address, access time, requested resource, amount of data transferred, browser/device information and technical status information to the extent logged by the web server.
This processing is carried out to provide the website securely and reliably and, where the website is used to initiate care services, to take pre-contractual steps. The relevant legal bases include Art. 6(1)(f) and, depending on the request, Art. 6(1)(b) GDPR.
STRATO provides a data-processing agreement under Art. 28 GDPR. Before go-live, Dream Team must ensure that the DPA applicable to the specific STRATO contract is documented.
4. General legal bases and retention
Depending on the processing activity, we rely in particular on Art. 6(1)(b) GDPR (contract or pre-contractual steps), Art. 6(1)(c) GDPR (legal obligations), Art. 6(1)(f) GDPR (legitimate interests in secure communication and website operation) and, where expressly requested, Art. 6(1)(a) GDPR (consent).
Care grade and selected care services may constitute health data within the meaning of Art. 9 GDPR. The public request forms therefore ask for explicit consent to process those details (Art. 9(2)(a) GDPR). Consent can be withdrawn for the future.
Data is generally deleted when the purpose of processing no longer applies and no statutory retention duty or other lawful reason requires continued storage. The standard periods for the individual flows are described below.
5. SSL/TLS encryption and technical security
The website is provided over HTTPS. This encrypts data in transit between the browser and the web server. Nevertheless, complete protection of every form of internet communication against all risks cannot be guaranteed.
6. General contact form and contact by email/phone
If you use the general contact form, we process your name, email address, optional phone number and message in order to handle your enquiry. The new theme does not store the message as a separate contact record in the WordPress CMS; it forwards the message to the recipient address configured in the backend.
Please do not send diagnoses, medical reports, medication plans or other particularly sensitive health information through the general contact form. Depending on the enquiry, the legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR.
To protect the forms against automated abuse, the website does not use an external CAPTCHA platform. Instead, it uses an invisible honeypot field, a signed minimum-completion-time check and short-lived server-side rate limiting. For rate limiting, the technically available IP address is converted into a salted, non-reversible verification value; the theme does not store the raw IP address. The verification value is used only for abuse prevention and expires after a short period (normally 15 minutes). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the security and availability of the website).
7. Care request and non-binding cost estimate
For a care request, the website processes the selected services and frequencies, care grade, requested start date, name, address, ZIP/city, phone number and optional email address. Prices and insurance limits are used only for a non-binding website estimate if confirmed values have been entered in the backend.
The request is forwarded by email to the configured Dream Team address and is not stored as a patient record in the CMS. Explicit consent to process the care-related information is mandatory in the form.
The specific internal standard retention period has not yet been confirmed in the staging backend and must be set before go-live.
8. §37.3 consultation request
For existing customers, the form asks for name, phone number, care grade and preferred date/time window. New customers are additionally asked for address, ZIP/city and care insurance provider. Diagnoses and medical documents are not requested.
The data is forwarded by email to the configured recipient in order to handle the request and arrange the consultation. The form asks for explicit consent for the processing of care-related details.
The specific internal standard retention period has not yet been confirmed in the staging backend and must be set before go-live.
9. Job applications and CVs
For an application, we process name, phone, email, desired position, employment type, desired weekly hours, earliest start date, Class B driving-licence information and the uploaded CV. Processing is carried out for the recruitment process, in particular on the basis of Art. 6(1)(b) GDPR together with the applicable rules governing applicant and employment data.
The theme stores the uploaded CV on the web server only temporarily, sends it as an attachment to the configured recruitment address and then deletes the temporary server copy. The application received by email is subsequently subject to Dream Team's internal recruitment and deletion policy.
The specific internal standard retention period has not yet been confirmed in the staging backend and must be set before go-live.
10. Service-area check
Browser location permission
If you voluntarily select “Check my location”, your browser asks for location permission. The coordinates obtained by the browser are compared locally by the theme code with the service radius configured in the backend. For this direct radius comparison, the theme code does not send those coordinates to Dream Team or to a map provider. The browser or operating system may use its own location services to determine your position.
Address/ZIP geocoding
An external address/ZIP geocoding function is currently disabled. If it is enabled later, this section will expand automatically and the function must be reviewed again for privacy compliance before go-live.
11. Cookies, fonts and external content
The Dream Team Modern theme does not embed external Google Fonts, analytics or marketing services. The design uses local/system fonts. WordPress may set technically necessary cookies, particularly for logged-in administrators and security functions.
If optional tracking, maps, video, reCAPTCHA or other external services are activated later, consent management and this privacy policy must be updated and reviewed again accordingly.
12. Recipients and processors
Internally, personal data is available only to the persons or departments that need it to handle the relevant matter. Technical service providers receive data only where necessary for the service and where permitted by data-protection law. STRATO is intended to act as the technical hosting provider. Other recipients – in particular a separate email provider – must be checked against the actual configuration before go-live and added where necessary.
13. Your rights
Subject to the statutory conditions, you have rights including access, rectification, erasure, restriction of processing and data portability. Consent can be withdrawn for the future. Where processing is based on Art. 6(1)(f) GDPR, you may object subject to the statutory conditions. You also have the right to lodge a complaint with a competent data-protection supervisory authority.
14. Version and changes
This privacy policy was restructured for the STRATO staging migration and the functions of the Dream Team Modern theme. It must be reviewed again whenever hosting, email delivery, plugins, tracking, map/geocoding services, forms or internal deletion periods change.