Controllers
Reisemedizin Tirol is run as an Ordinationsgemeinschaft (shared-premises practice association) made up of two independent sole practices. Under data protection law, each doctor is therefore the controller for their own practice:
Dr Marco Schönberger
Dr Laura Riepl
Bahnhofstraße 54, 6300 Wörgl
Telephone: +43 (0) 5332 / 25900
Electronic contact: Medflex (end-to-end encrypted)
Data protection contact: Dr Marco Schönberger
1. General information
The protection of your personal data is of particular importance to us. We therefore process your data exclusively in accordance with the relevant legal provisions (GDPR, TKG 2021). This privacy policy informs you about the key aspects of data processing in connection with our website and our travel medicine practice.
2. Collection and processing of personal data
We process personal data that you provide to us when using our website, when contacting us, or during the course of your medical care:
- Name, address, contact details (email, telephone number)
- Health data (medical history, vaccination status, diagnoses, test results)
- Insurance details
3. Purpose of data processing
Data is processed for the following purposes:
- To fulfil our medical and contractual obligations, particularly in the field of travel medicine and vaccinations
- To comply with legal requirements
- Practice organisation and appointment management
- To communicate with you
4. Legal bases
- Health data for treatment: Art. 9(2)(h) GDPR in conjunction with the Austrian Medical Practitioners Act 1998 (Ärztegesetz 1998).
- Treatment contract: Art. 6(1)(b) GDPR.
- Legal obligations such as documentation, billing and retention: Art. 6(1)(c) GDPR.
- Consent, where we expressly ask you for it: Art. 6(1)(a) GDPR. You can withdraw consent you have given at any time with effect for the future.
5. Disclosure of data
We will only disclose your data if it is required by law, if you have given your consent, or if it is necessary for us to provide our services. Recipients may include:
- Laboratories and other healthcare providers
- Billing and claims-settlement bodies and social security providers
- IT service providers (e.g. maintenance, hosting)
We have data processing agreements under Art. 28 GDPR with the following service providers:
- Medflex – encrypted communication with patients
- Quickticket – issuing acute appointments
- ClickDoc – online appointment booking
- LimeSurvey – patient surveys
- CGM Maxx – practice software and data centre
- Mistral AI – chatbot on the website
- Friendly Captcha – protection against misuse in the chat window
6. Your rights
You have the right to access, rectify, erase, restrict the processing of, and transfer your data. You may also object to the processing of your data and withdraw your consent. Medical records – in particular vaccination and travel records – are subject to statutory retention requirements and cannot therefore be deleted immediately. Under section 51 of the Austrian Medical Practitioners Act 1998 (Ärztegesetz 1998), we keep patient records for at least ten years from the last treatment.
To exercise these rights, please contact us by post at the address given above or via Medflex.
You also have the right to lodge a complaint with the supervisory authority. The competent authority is the Österreichische Datenschutzbehörde (the Austrian data protection authority, www.dsb.gv.at).
7. Data security
We employ technical and organisational security measures to protect your data as effectively as possible against unauthorised access, loss or misuse.
8. Communication channels & services
To ensure secure communication, we use only encrypted services:
- Proton Mail: end-to-end encrypted, zero-access
- Threema Work: A secure messaging app for internal communication
- Medflex: A platform for GDPR-compliant medical data exchange
- ELGA: The legally regulated part of the electronic health record
- DAME/MEDICALNET: Digital healthcare services for connecting medical practices, sharing test results, etc.
Our encrypted communication services are operated in Switzerland. The European Commission has issued an adequacy decision for Switzerland, so a transfer there is treated in the same way as a transfer within the EU. No transfer to any other third country takes place.
9. Website: cookies and embedded content
This website sets no cookies. For web analytics we use Matomo — deliberately configured to work without cookies and to store nothing on your device (see the following section). Our Cookie Policy sets out which entries are stored in your browser to operate the site and which content is loaded from third parties only after a click.
10. Web analytics with Matomo
We use Matomo, an open-source web analytics tool operated on our own infrastructure — visitor data is never passed to third parties. Matomo is deliberately configured to work without cookies and stores nothing on your device. Your IP address is shortened (anonymised) before storage, and your browser’s “Do Not Track” setting is respected. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in an anonymised analysis of how our website is used.
11. Chatbot “Klaus”
On our website you can ask questions about our practice in a chat window. The chatbot is called Klaus. You are chatting with an AI assistant – we say so in the chat window before you enter anything. Klaus provides no medical information and does not replace a consultation with a doctor.
Please do not enter health data or personal details in the chat. We do not need them there. If you do so nonetheless, that information constitutes health data within the meaning of Article 9 of the GDPR.
Transmission to Mistral AI. Every entry you make is transmitted from our server to Mistral AI – including when the answer then comes from us, because the first step is always a classification of your question by a language model. Mistral AI is based in Paris; we use the EU endpoint exclusively, so processing takes place within the European Union. A data processing agreement in accordance with Article 28 of the GDPR is in place. Your entries are not used there to train models. We have also expressly agreed with Mistral AI that your entries are not stored there (Zero Data Retention): your message is processed in order to answer it and is not kept afterwards. That is a deliberate choice of a European provider and of the most sparing handling of your data that we were able to achieve.
Answers about hours, directions and contact come from us. Opening hours, telephone number, address, parking, accessibility, appointments, prescriptions and the emergency numbers are answered by our own server from the maintained practice data. The language model does not phrase those answers.
Recording. We record the course of every chat: your entries, our answers and technical details of the exchange. The conversation content is encrypted immediately. The key needed to read it is not on the web server – that server can create records but cannot open them. After twelve months they are deleted automatically.
The purpose of the recording is traceability: if an answer is complained about, we must be able to establish what was actually said. The legal basis is Article 6(1)(f) of the GDPR (legitimate interest) and, in so far as health data arises, Article 9(2)(f) of the GDPR (establishment, exercise or defence of legal claims).
Access and erasure. The records are encrypted and contain nothing by which we could assign them to a particular person. We therefore cannot locate an individual conversation – not even on request (Article 11 of the GDPR). Your protection here comes from the encryption and the limited storage period, not from erasure on request.
Protection against misuse. To prevent misuse and excessive costs, our server records for at most one hour how many requests originated from an internet connection. Your IP address is not stored, only an irreversible check value derived from it. In addition, a service provided by Friendly Captcha GmbH (Am Anger 3-5, 82237 Woerthsee, Germany) checks whether the request comes from a human. Your browser connects to this service only once you open the chat window – not before. Friendly Captcha sets no cookies, but does store technical data in your browser’s local storage (IndexedDB) to avoid repeated checks.
12. Amendments to this statement
We reserve the right to update this privacy policy. You can find the latest version on our website at any time.