1. Data Controller
The controller responsible for data processing on this website under the General Data Protection Regulation (GDPR) is:
Medlife GmbH
Otto-Hahn-Straße 39
63303 Dreieich
Germany
Telephone: +49 (6103) 830448
Email: info@medlifegmbh.de
2. Core Principles & Absence of Third-Party Tracking
The security and privacy of your commercial data are central to our operations. Our B2B web infrastructure is designed on the principle of data minimization:
- We deploy zero marketing or behavioral tracking scripts (no Meta Pixel, no LinkedIn Insight Tag).
- We do not utilize external web analytics platforms (no Google Analytics, no Google Tag Manager).
- We load no remote fonts; all typography is served directly through local system fonts on your operating device.
- We embed no external map iframes directly. Map links navigate to external services in a separate browser tab.
- We do not operate consumer email newsletters, marketing automation databases or profiling algorithms.
- There are no public user accounts or stored login profiles on this site.
3. Server Access Logs
When accessing our website, our server infrastructure automatically records technical log entries transmitted by your browser. These include:
- IP address of the accessing system
- Date and time of server access
- Name and URL of the retrieved resource
- Referrer URL (the previous website, if provided by the client)
- Browser client type, version, and operating system
The legal basis for processing is Art. 6 (1) (f) GDPR based on our legitimate interest in the technically stable, performant, and secure delivery of our web services. Server access logs are cleared regularly in accordance with routine security retention schedules of our German hosting provider.
4. Commercial Enquiries and B2B Quotation Form
When you submit a quotation request via our B2B contact form, email, or telephone, we process the supplied corporate information (including company name, contact person, business email address, telephone number, destination country, requested product lines, and message content).
Legal Basis: Data processing is conducted pursuant to Art. 6 (1) (b) GDPR for the performance of pre-contractual commercial measures and quotation preparation, as well as Art. 6 (1) (f) GDPR (legitimate commercial interest in processing business communications).
Spam Mitigation & Rate Limiting: To safeguard server integrity from automated bot submissions and denial-of-service attempts, we utilize server-side security mechanisms (honeypot fields, completion timing verification, and IP-hash rate limiting). IP hashes are pruned automatically after a maximum of 30 minutes. We do not correlate hashes with external datasets or disclose them to third parties.
Data Retention: Information resulting from business proposals and commercial contracts is retained in compliance with statutory commercial and tax retention mandates under German law (§ 257 HGB, § 147 AO) and deleted thereafter.
5. Cookie Policy
Our website employs no tracking, analytics, or behavioral advertising cookies. Consequently, no intrusive cookie consent banner is presented.
We utilize only a single, strictly necessary technical session cookie to protect form transmissions against Cross-Site Request Forgery (CSRF). This cookie contains solely a randomly generated alphanumeric session token, is fortified with HttpOnly, SameSite=Lax, and (under HTTPS) Secure flags, and expires immediately upon closing your browser session.
The legal basis for this technical session cookie is § 25 (2) No. 2 TDDDG in conjunction with Art. 6 (1) (f) GDPR.
6. Data Subject Rights
Under Chapter III of the GDPR, you possess the following statutory rights regarding your personal data:
- Right of Access (Art. 15 GDPR): You may request confirmation and information regarding processed personal data.
- Right to Rectification (Art. 16 GDPR): You have the right to obtain the correction of inaccurate personal data.
- Right to Erasure (Art. 17 GDPR): You may request deletion of your personal data unless statutory retention duties apply.
- Right to Restriction of Processing (Art. 18 GDPR): You may request restriction of data processing under statutory conditions.
- Right to Data Portability (Art. 20 GDPR): You have the right to receive your data in a structured, standard, machine-readable format.
- Right to Object (Art. 21 GDPR): You possess the right to object at any time to data processing based on legitimate interests.
To exercise any of these rights, please contact our privacy desk directly via email: info@medlifegmbh.de.
7. Right to Lodge a Complaint with a Supervisory Authority
In accordance with Art. 77 GDPR, you have the right to lodge a formal complaint with a competent data protection supervisory authority. The competent authority for our corporate seat in Hesse, Germany is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Gustav-Stresemann-Ring 1
65189 Wiesbaden, Germany
Website: https://datenschutz.hessen.de/