
Privacy
Privacy policy
Last updated: 26 September 2026
1. Controller and contact
Cardiotronic GmbH, Subbelrather Str. 15 A, 50823 Cologne, Germany, represented by Managing Director Ramin Salimi Amin. For privacy enquiries and to exercise your rights, contact sales@cardiotronic.de.
2. Hosting and technical operation
Our website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. Requests involve processing IP addresses, timestamps, requested pages, referrer URLs, browser and operating-system details and technical status information to deliver, maintain and secure the website and diagnose errors. The legal basis is Article 6(1)(f) GDPR, reflecting our legitimate interest in secure, reliable operation. Technical logs are deleted once no longer needed for their purpose; incident-related data may be needed longer for investigation and legal claims. Provider information: IONOS privacy policy.
3. Cookies and consent management
We use Borlabs Cookie by Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg, Germany, to record and apply your choices about optional services. It processes your consent choices and technical assignment information. The consent cookie is configured for 182 days. You can change or withdraw your choices at any time through the cookie settings. Withdrawal applies to future processing.
Strictly necessary storage or access on your device is based on section 25(2) TDDDG. Optional storage or access requires your consent under section 25(1) TDDDG. Subsequent processing of personal data for optional services is based on Article 6(1)(a) GDPR. Managing and recording consent relies on Article 6(1)(c) GDPR; necessary technical operation relies on Article 6(1)(f) GDPR. Open cookie settings
4. Contact form and email
When you contact us, we process your contact details, company information, enquiry and any additional information you provide to respond and prepare cooperation. The legal basis is Article 6(1)(b) GDPR for your own pre-contractual or contractual matters, otherwise Article 6(1)(f) GDPR based on our interest in handling business enquiries. Where consent is obtained, Article 6(1)(a) GDPR also applies. Providing information is voluntary, but insufficient contact or factual details may prevent us from responding. Please do not send patient data or other sensitive health information through the form or general contact channels.
Form messages are sent through IONOS. To monitor delivery, FluentSMTP stores sending logs, including email content, on our web server for 14 days. Enquiries in our mailbox and business systems are retained to handle them and, where relevant, perform a contract. They are then deleted unless statutory retention duties or evidence needed to establish, exercise or defend legal claims require otherwise.
5. WhatsApp and LinkedIn
Our WhatsApp and LinkedIn buttons are external links. Only opening them takes you away from our website and connects you to the respective service. In the European Economic Area, the providers are WhatsApp Ireland Limited and LinkedIn Ireland Unlimited Company. They process technical connection data and, where applicable, account information under their own terms. If you message us there, we process your message and profile information to respond on the legal bases described in section 4. Use is voluntary; email and our contact form remain available. Further information: WhatsApp privacy policy and LinkedIn privacy policy.
6. Google Maps and external images
A Google Maps map can be loaded on our contact page. For users in the EEA, the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The map loads only after your consent. IP addresses, browser information and the page visited may be transmitted to Google, and information may be stored on or read from your device. The purpose is to show our location and help you plan your visit. The legal bases are Article 6(1)(a) GDPR and section 25(1) TDDDG. Consent can be withdrawn in the cookie settings. Our address remains readable without the map. Google privacy policy.
WHX and MEDICA event logos load from external image servers at knect365.imgix.net and medica.de. This technically transmits your IP address and image-request information to those providers to display the events. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is clear information about opportunities to meet us. Linked organiser websites are governed by their own privacy notices.
7. Security and fonts
We use Wordfence and Limit Login Attempts Reloaded to protect against attacks and abusive logins. They process IP addresses, timestamps, requested URLs and security events. Wordfence is configured to log security-related traffic only; these traffic logs are stored for a maximum of 30 days. Attack-related data may be required longer for investigation and legal claims. Wordfence is provided by Defiant, Inc., USA; its security functions may transmit technical attack and connection data to the provider. The legal basis is Article 6(1)(f) GDPR, reflecting our interest in protecting the website and its users. Further information: Wordfence privacy policy. Fonts are hosted locally; no connection to Google Fonts is required for this.
8. Recipients and international transfers
Personal data is accessible to the staff responsible for your enquiry and necessary technical service providers. Disclosure occurs only where required for the stated purposes or supported by a legal basis. External services may process data outside the EU or EEA. An adequacy decision under Article 45 GDPR may provide a basis; for the USA, the EU-US Data Privacy Framework applies only to appropriately certified recipients. Otherwise, appropriate safeguards under Article 46 GDPR, such as EU standard contractual clauses, or a statutory exception are required. Information about applicable safeguards is available from us and the linked provider notices.
9. Your rights
Subject to the statutory conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18) and portability (Article 20). You can withdraw consent at any time for the future without affecting the lawfulness of earlier processing.
Right to object: Where processing relies on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation (Article 21 GDPR). You may object to direct marketing at any time without giving reasons.
You may complain to a supervisory authority, particularly where you habitually reside or work or where an alleged infringement occurred. The authority responsible for our registered office is the North Rhine-Westphalia Commissioner for Data Protection and Freedom of Information. We do not use enquiry data for solely automated decisions producing legal or similarly significant effects.