+49 (0) 40 / 25331867 Mon - Fri: 09:00 - 17:00 Wandsbeker Chaussee 1, 22089 Hamburg
Telephone and video consultation Interdisciplinary medicine under one roof

Privacy Policy

Last updated: June 2026
We take the protection of your personal data seriously. Below we inform you which data is processed when you visit this website and use the contact form, appointment request form, waitlist form or medical history form.

1. Controller

Dr. med. Ali Erdogan
Medical practice Dr. med. Ali Erdogan
Wandsbeker Chaussee 1
22089 Hamburg
Germany

Phone: 040 / 25 33 18 67
Email: datenschutz@drerdogan.de

2. General information on data processing

We process personal data only to the extent necessary to provide this website, respond to your request, fulfill legal obligations or on the basis of your consent. The relevant legal bases include in particular Art. 6 (1) lit. a, b, c and f GDPR. Where special categories of personal data, in particular health data, are concerned, processing takes place only within the legally permitted framework, in particular pursuant to Art. 9 (2) lit. h GDPR or on the basis of your explicit consent.

3. Website provision and server log files

When this website is accessed, technically necessary access data is processed. This may include in particular the IP address, date and time of access, requested URL, referrer URL, browser and device information, operating system, language settings and the requesting provider.

Processing is carried out to provide the website securely and reliably, to analyze errors, to prevent attacks and for technical optimization. The legal basis is Art. 6 (1) lit. f GDPR. Our legitimate interest lies in the secure and trouble-free operation of this website.

Log data that is no longer required is deleted or anonymized. Online visitor data in the application is anonymized with regard to the IP address no later than after seven days, unless longer storage is required for security reasons.

4. Hosting

This website is hosted by an external hosting service provider. The provider is netclusive GmbH, Robert-Bosch-Str. 10, Haus I, 56410 Montabaur, Germany.

The hosting service provider processes technical data generated during operation of the website, in particular server log files, technical communication data and content data, insofar as this is necessary for the operation, security and maintenance of the website. Processing is based on Art. 6 (1) lit. f GDPR and, where required, on the basis of a data processing agreement pursuant to Art. 28 GDPR.

5. Contact form and contact requests

If you contact us via the contact form or by email, we process the information you provide in order to handle your request. Depending on your entries, this may include your name, email address, telephone number, subject, message, voluntary additional information and technical data such as IP address, browser identifier, language, time of request and your confirmation of the privacy notice.

Please only submit the information via the general contact form that is necessary for your request. Medical information may constitute special categories of personal data. If you voluntarily provide such information, we process it solely to handle your request and within the framework of medical confidentiality.

The legal basis is Art. 6 (1) lit. b GDPR if your request concerns treatment, appointment coordination or other pre-contractual or contractual communication. Otherwise, processing is based on Art. 6 (1) lit. f GDPR. For health data, Art. 9 (2) lit. h GDPR or Art. 9 (2) lit. a GDPR also applies if you have given explicit consent.

Your request is stored in the website database and sent to the practice by email. The data is deleted as soon as the request has been fully processed and no statutory retention obligations or legitimate documentation interests prevent deletion.

5a. Medical history form and document uploads

If you use the medical history form, we process the information you submit in order to prepare your appointment and support treatment-related communication. This may include identification and contact data, date of birth, insurance information, treatment area, appointment type, symptoms, known diagnoses, previous treatments, medication, allergies, substance use, family history, uploaded documents and technical data such as IP address, browser identifier, language and time of submission.

The information may include special categories of personal data, in particular health data. Processing is based on your explicit consent pursuant to Art. 9 (2) lit. a GDPR and, where applicable, Art. 9 (2) lit. h GDPR, as well as Art. 6 (1) lit. b GDPR for appointment preparation and treatment-related communication.

The submitted data is stored in the website database and sent to the practice by email. Uploaded documents are stored in a protected upload area on the server and are made available only to authorized practice staff in the protected administration and team area. Direct public access to the upload directory is blocked.

Please do not use the medical history form for emergencies. If you withdraw your consent, processing carried out before the withdrawal remains lawful. Statutory retention obligations and medical documentation obligations may continue to apply.

5b. Waitlist form

If you use the waitlist form, we process the information you submit in order to manage appointment requests and contact you if appointment capacity becomes available. This may include your first name, last name, email address, phone number, insurance type, treatment area, patient status, preferred contact method, availability, optional message, language, IP address, browser identifier and time of submission.

The waitlist entry is not an appointment confirmation and does not replace medical advice. Please do not use the waitlist form for emergencies or urgent medical concerns.

The submitted data is stored in the website database and sent to the practice by email. Processing is based on your consent pursuant to Art. 6 (1) lit. a GDPR and, where applicable, on Art. 6 (1) lit. b GDPR for appointment-related communication.

5c. Appointment request form

If you use the appointment request form, we process the information you submit in order to assign and process appointment requests, cancellations, rescheduling requests or appointment-related questions. This may include your first name, last name, date of birth, email address, phone number, preferred contact method, appointment date and time, preferred period, message, language, IP address, browser identifier and time of submission.

The appointment request form is not an appointment confirmation and is not intended for emergencies. Please do not submit diagnoses or urgent medical information through this form.

The submitted data is stored in the website database and sent to the practice by email. Processing is based on your consent pursuant to Art. 6 (1) lit. a GDPR and, where applicable, on Art. 6 (1) lit. b GDPR for appointment-related communication.

6. Email communication

We use technical service providers and SMTP servers to send and receive emails. In this context, email address, name, message content, technical sending data and delivery information may be processed in particular.

Automatic confirmation emails from the contact form, appointment request form, waitlist form or medical history form may contain a technical tracking pixel that can record when the email is accessed. This serves technical delivery and communication control. The legal basis is Art. 6 (1) lit. f GDPR.

7. Cookies, local storage and consent management

This website uses technically necessary storage technologies, in particular session data and local storage of your cookie selection. These are required to provide security functions, form protection, language settings and consent management. The legal basis is Art. 6 (1) lit. f GDPR; access to strictly necessary information takes place without consent pursuant to Section 25 (2) TDDDG.

Optional categories such as analytics, marketing or external media are only activated if you have given your consent via the cookie banner. The legal basis is Art. 6 (1) lit. a GDPR in conjunction with Section 25 (1) TDDDG. You can change your selection at any time via the cookie settings.

8. Google Maps

A Google Maps map can be embedded on the contact page. The map is only loaded when you explicitly activate the display. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

When the map is loaded, data such as your IP address, browser information, location or usage data and the page accessed may be transmitted to Google. Data may also be transferred to Google LLC in the USA. The legal basis is your consent pursuant to Art. 6 (1) lit. a GDPR and Section 25 (1) TDDDG.

Further information can be found in Google privacy policy: https://policies.google.com/privacy

9. Recipients of personal data

Personal data is only transmitted to recipients where this is necessary for the purposes mentioned. Recipients may include hosting and email service providers, IT service providers, the practice administration and legally authorized bodies. Data is not passed on for advertising purposes.

10. Transfers to third countries

Personal data is transferred to countries outside the European Union or the European Economic Area only if this is required for the use of an embedded service, if you have consented, if an adequacy decision exists or if appropriate safeguards pursuant to Art. 44 et seq. GDPR are in place.

11. Storage period

We store personal data only for as long as necessary for the respective purposes. Afterwards, the data is deleted or anonymized unless statutory retention periods, documentation obligations or legitimate interests in further storage apply.

12. Your rights

Under the GDPR, you have the right to information, rectification, erasure, restriction of processing, data portability and objection to certain processing activities. If processing is based on your consent, you may withdraw it at any time with effect for the future.

To exercise your rights, you can contact us at any time: datenschutz@drerdogan.de

13. Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. In particular, the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, is responsible.

Further information: datenschutz-hamburg.de

14. Obligation to provide data

Providing personal data is generally not legally required for visiting the website. For use of the contact form, appointment request form, waitlist form or medical history form, the information marked as mandatory is required. Without this information, we cannot process your request or can only process it to a limited extent.

15. Automated decision-making

Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place.

16. Changes to this Privacy Policy

We may amend this Privacy Policy if legal requirements, technical functions or data processing activities change. The version published on this page applies.