Privacy Policy – Adon Health Skip to content
Hervorragend
4,5/5
10.000+ Männern geholfen
Cart

Data protection information for customers and patients of Adon Health UG

(As of December 2025)

1. Subject of this data protection information

This privacy notice informs you, in accordance with Article 13 of the General Data Protection Regulation (GDPR), about how personal data is processed by Adon Health UG when you use services provided by Adon Health UG. In particular, you will receive information about the type, scope, purposes, and legal basis of data processing, about possible recipients of personal data, and about your rights as a data subject.

This privacy policy applies exclusively to customers and patients of Adon Health UG and relates to the processing of personal data in connection with the ordering and execution of test kits, the organization and provision of laboratory services and results, the facilitation of telemedicine consultations with independent partner physicians, the transmission of prescriptions to pharmacies, and, if expressly requested, the use of personal data for scientific or quality assurance purposes. The processing of personal data in connection with the purely informational use of the website is not covered by this privacy policy.

2. Responsible person

The controller within the meaning of Article 4 No. 7 GDPR for the processing operations described in this privacy notice is the

Adon Health UG (limited liability),
Falkenstraße 11F
81541 Munich, Germany
Email: support@adon-health.de

If you have any questions or technical problems with our platform, you can contact us by email at hallo@adon-health.de .

Adon Health is not a medical facility and does not provide medical services itself. The company operates a digital platform that coordinates and facilitates the organizational, technical, and administrative provision of medical services from independent third parties.

3. Data Protection Officer

We have appointed a data protection officer in accordance with Article 37 of the GDPR. This officer monitors compliance with data protection regulations within our company and is available to you as an independent contact person for all questions relating to the processing of your personal data and the exercise of your rights as a data subject.

You can contact our data protection officer confidentially at any time, especially if you have questions about this privacy policy, the processing of your personal data or your rights under the GDPR.

Contact details of the data protection officer:

Email: dsgvo@datendo.de

Regardless of whether you contact our data protection officer, you are free to contact us directly or the responsible data protection supervisory authority at any time with regard to data protection concerns.

4. Categories of personal data

When using Adon Health's services, personal data is processed, either provided by you or generated during the course of service provision by participating cooperation partners. This includes general personal data, in particular identity, contact, contract, billing, and organizational data.

Furthermore, depending on the specific scope of services, special categories of personal data within the meaning of Article 9(1) GDPR are processed. These include, in particular, health data such as information on symptoms, complaints, pre-existing conditions, medication, results of medical questionnaires, laboratory values, as well as medical findings and prescription information.

5. Origin of the personal data

Personal data is generally collected directly from you, particularly during order, registration, and booking processes, as well as through medical questionnaires you complete. Furthermore, personal data may originate from cooperation partners, especially laboratories in connection with conducting laboratory analyses, and from cooperating physicians in connection with telemedicine consultations and medical prescriptions. Finally, personal data may be obtained from service providers, insofar as this is necessary for the provision of services.

6. Purposes and legal bases of processing

6.1 General Principles

Personal data is processed only to the extent and for as long as this is necessary for the provision of the services you have requested or as required by law. Where general personal data is processed, the processing is based, depending on the specific processing operation, on Article 6(1)(b) GDPR if the processing is necessary for the performance of a contract, or on Article 6(1)(c) GDPR if there are statutory retention obligations.

Insofar as special categories of personal data, in particular health data, are processed, this is done exclusively on the basis of your prior, explicit consent pursuant to Art. 9 para. 2 lit. a GDPR in conjunction with Art. 6 para. 1 lit. a GDPR. Without such consent, the provision of the corresponding services is generally not possible.

6.2 Ordering and execution of test kits and laboratory process

When you order a test kit, Adon Health processes your personal data to process the order, uniquely assign the test kit to you, collect medical questionnaire data, arrange the laboratory analysis, receive the laboratory results, and provide them to you. At your explicit request, the laboratory results can also be transmitted to a cooperating physician of your choice. The processing of the necessary health data is a mandatory prerequisite for carrying out the laboratory process.

6.3 Payment processing

Payment processing is handled by external payment service providers. Adon Health regularly receives only billing-related information such as payment status or transaction references, but not complete payment data such as credit card numbers. Payment data is processed for the purpose of fulfilling the contractual relationship and complying with legal accounting and retention obligations.

6.4 Facilitation and organization of telemedicine consultations

If you schedule a telemedicine consultation via the platform, Adon Health processes personal data for appointment scheduling, the technical execution of the video consultation, and organizational documentation at the platform level. The medical treatment itself is provided exclusively by your chosen partner physician.

7. Division of roles between Adon Health and cooperating physicians

The cooperating physicians involved in your treatment process your personal data as independent controllers within the meaning of Art. 4 No. 7 GDPR and independently fulfill their data protection information and accountability obligations.

In contrast, Adon Health processes personal data for the organization, coordination, and technical support of the platform services. Insofar as Adon Health acts on behalf of a physician, for example, by providing practice management software, technical documentation, or sending documents or invoices on behalf of the physician, this processing is carried out as commissioned data processing pursuant to Article 28 GDPR. In these cases, the respective physician is the data controller, and Adon Health is the data processor.

8. Transmission of prescriptions to pharmacies

At your express request, Adon Health processes personal data in order to transmit a doctor-issued prescription to a pharmacy of your choice. This processing also takes place exclusively on the basis of your consent.

9. Processing for scientific and quality assurance purposes

Provided you have given your separate consent, personal data may be processed for scientific or quality assurance purposes. This processing is carried out either in pseudonymized form based on your consent or in completely anonymized form. Anonymous data is data that cannot be directly or indirectly attributed to a specific person; in this case, the GDPR does not apply. Publications are made exclusively in aggregated or anonymized form.

10. Recipients of personal data and access restrictions

Within Adon Health UG, access to your personal data is restricted to those employees who absolutely require this data to fulfill the purposes described in this privacy policy. Access is limited to the necessary minimum and is based on a binding role and authorization concept. All employees are bound by confidentiality agreements and receive regular data protection training.

Your personal data will only be transferred to external recipients if this is necessary for the provision of the services you have requested or if you have expressly consented to this. This applies in particular to the transfer of data to medical cooperation partners as well as to technical and organizational service providers involved in the provision of services.

As part of our laboratory services, we transmit the personal data required for the analysis, including health data, to our laboratory partner Remi Health GmbH, Am Mühlenberg 11, 14476 Potsdam, and to the laboratory actually performing the analysis, currently in particular the MOMA Test Laboratory, Am Mühlenberg 11, 14476 Potsdam. This transmission is solely for the purpose of conducting the laboratory analysis and transmitting the test results. The aforementioned laboratory partners process your data in accordance with their respective medical and legal obligations.

If you decide to undergo a telemedicine consultation, we will transmit the necessary personal data, in particular master data, contact details, relevant medical history data, and laboratory results, to your chosen treating physician. The respective physician processes your personal data within the scope of your medical treatment as an independent controller within the meaning of Article 4 No. 7 GDPR. The treating physician is responsible for fulfilling all data protection information obligations related to the medical treatment.

At your express request, we will also transmit the personal data required for filling a medical prescription, in particular prescription data as well as contact and identification data, to the pharmacy you have selected. The pharmacy also processes your personal data as an independent controller within the framework of legal requirements.

For the technical and organizational implementation of our services, we also use selected IT and service providers. These service providers only receive access to personal data to the extent necessary for the provision of the respective services and process the data exclusively on our instructions.

This includes in particular:

  • Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, and Shopify International Ltd., 2nd Floor, 1–2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland, are used as payment and processing service providers. These service providers process payment and billing-related data to complete payment processing. Adon Health does not regularly receive complete payment data, but only payment status and billing information. For further information on data transfers to Stripe Inc., please refer to Stripe's privacy policy and Shopify's privacy policy .
  • Shopify International Ltd., 2nd Floor, 1–2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland, provides the e-commerce platform. Shopify, acting as a data processor, processes identification and contact data, order and transaction data, as well as usage and shop activity data. Further information can be found in Shopify's privacy policy .

  • RED Medical Systems GmbH, Lutzstraße 2, 80867 Munich, whose practice management software we use to manage and securely store health data together with your chosen doctor. Insofar as we operate this software on behalf of the doctor or provide technical support services, the processing is carried out as commissioned data processing in accordance with Article 28 GDPR.
  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, (Google Workspace / Gmail) for the purpose of conducting individual digital customer communication, in particular for processing inquiries, contractual communication, and sending service-related information via email. The following personal data may be processed in this context: contact details (e.g., name, email address), contract and customer data, communication content (e.g., email content, attachments, metadata such as sending and receiving times).
  • For the secure and encrypted transmission of personal data, especially in exchanges with laboratories and medical cooperation partners, we use the service of Zivver BV, Spaklerweg 52, 1114 AE Amsterdam, Netherlands.
  • Sendinblue GmbH, trading under the brand Brevo, Köpenicker Str. 126, 10179 Berlin, processes data for the management and execution of digital customer communication, in particular for sending emails in connection with existing or pending contractual relationships (e.g., service information, reminders, follow-ups, and – if consent has been given – marketing emails). The following personal data may be processed in this context: contact details (e.g., name, email address), contract and customer data (e.g., status, product or service reference), and communication data (e.g., email sending, opening, and clicks).
  • For the technical implementation of telemedicine consultations, we, together with the treating physician, utilize the services of Facharzt-Sofort GmbH (Viomedi), Marktplatz 30, 94431 Pilsting, which provides the necessary secure video communication infrastructure.
  • We use Zapier, Inc., 548 Market St. #62411, San Francisco, CA 94104-5401, United States, as an automation and integration service to technically link various software services we use and to automate processes (e.g., transferring status information, triggering workflows, or synchronizing selected data). In the course of this technical processing, Zapier may temporarily gain access to personal data, in particular: identification and contact data (e.g., name, email address), contract and customer data (e.g., status information), and technical process and metadata (e.g., timestamps, trigger information).

Zapier is used exclusively for technical forwarding and automation and not for independent analysis or use of the data.

  • We use Zendesk, Inc., 181 Fremont Street, 17th Floor, San Francisco, CA 94105, United States, as a support and ticketing system to systematically record, process and document customer and patient requests.

Zendesk is primarily used for processing support requests, communication within the framework of existing or pending contractual relationships, and documenting the support process. The following personal data may be processed in this context: identification and contact data (e.g., name, email address), contract and customer data, communication content (e.g., requests, replies, attachments), support and process data (e.g., ticket status, timestamps, internal notes), and technical metadata (e.g., timestamps).

Support requests may also contain health-related information, provided this is communicated by the customer or patient.

  • Klaviyo, Inc., 125 Summer Street, Floor 6, Boston, MA 02110, United States, for the management and execution of digital customer communication, in particular for sending emails in connection with existing or pending contractual relationships (e.g., service information, reminders, follow-ups, and – if consent has been given – marketing emails). The following personal data may be processed in this context: contact details (e.g., name, email address), contract and customer data (e.g., status, product or service reference), and communication data (e.g., email sending, opening, and clicks).
  • We use Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855, Luxembourg, as a cloud infrastructure to run our own software and to securely store, process and provide the data processed through it.

This infrastructure enables the operation of our systems for contract processing, patient administration, the provision of medical services, and the technical provision and security of data processing. In particular, the following personal data may be processed: identification and contact data (e.g., name, email address), contract and customer data, health-related data (e.g., information from medical histories, questionnaires, and treatment records), and technical usage and log data (e.g., access times, system logs).

  • We use Dropbox, Inc., 1800 Owens Street, San Francisco, CA 94158, USA (Dropbox Sign) as an electronic signature service to provide contracts and forms digitally, have them filled out and signed in a legally binding manner.

This includes, in particular, treatment contracts, master data forms, medical history forms, and medical questionnaires. The following personal data may be processed: identification and contact information (e.g., name, email address), contract and master data, health-related information from medical histories and questionnaires, signature and metadata (e.g., time of signing, IP address, document status).

  • Appointments for telemedicine consultations are arranged via the portal of eTermin GmbH, Mättivor 3, 6430 Schwyz, Switzerland. The personal data processed in this context is limited to the information necessary for scheduling the appointment. This processing is based on appropriate data protection safeguards.
  • We have concluded data processing agreements in accordance with Article 28 of the GDPR with all service providers who process personal data on our behalf. These agreements ensure that personal data is processed exclusively according to our instructions, maintaining confidentiality and adhering to appropriate technical and organizational security measures.
  • Cooperating physicians only have access, via the systems used, to the personal data of those patients with whom they have a specific treatment relationship. Access to the data of other clients is prevented by appropriate technical and organizational measures, in particular client and patient separation, role-based access concepts, and logging.

11. Transfer to third countries

Personal data will only be transferred to countries outside the European Union or the European Economic Area if there is a legal basis for doing so. In these cases, the transfer will be based on an adequacy decision by the European Commission or comparable suitable safeguards.

12. Storage duration

Personal data is stored only as long as necessary to fulfill the respective purposes or as required by law. Data processed based on consent is deleted after withdrawal of consent or when the processing purpose ceases to exist, unless legal retention obligations apply. Research data is deleted or anonymized after ten years at the latest.

13. Voluntary nature of data provision

Providing personal data is voluntary. However, without the data required for the respective services, these services cannot be provided.

14. Rights of data subjects

As a “data subject” within the meaning of Art. 4 No. 1 GDPR, you have certain inalienable rights (data subject rights).

Adon Health is obligated to guarantee these data subject rights and must also contractually obligate any data processors it engages to provide the best possible support in implementing these rights. In this respect, you are entitled to the following data subject rights:

  • Right of access (Article 15 GDPR): You have the right to obtain information from us about whether we process personal data concerning you and, if so, what data this is and for what purpose the processing is carried out.
  • Right to rectification (Article 16 GDPR): You have the right to have inaccurate or incomplete personal data that we have stored about you corrected.
  • Right to erasure (Article 17 GDPR): Under certain circumstances, you have the right to request that we erase your personal data. This right exists, for example, if the data is no longer necessary for the purposes for which it was collected or if you have withdrawn your consent.
  • Right to restriction of processing (Article 18 GDPR): Under certain circumstances, you have the right to restrict the further processing of your personal data. This right exists, for example, if you contest the accuracy of the data or if the processing is unlawful.
  • Right to data portability (Article 20 GDPR): You have the right to receive a copy of your personal data from us in a structured, commonly used and machine-readable format. You can also have this data transmitted to another controller, provided this is technically feasible.
  • Right to object (Article 21 GDPR): You have the right to object, on grounds relating to your particular situation, to the processing of your personal data. We will then no longer process your data unless there are compelling legitimate grounds for the processing.
  • Right to withdraw consent (Article 7(3) GDPR): If we process your personal data based on your consent, you can withdraw this consent at any time. The lawfulness of the processing up to the point of withdrawal remains unaffected.
  • Right to lodge a complaint with a supervisory authority (Article 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection regulations.

The responsible data protection authority is:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach

You can assert your data subject rights at any time by notifying Adon Health in writing or electronically using the contact details provided in the "Controller" section of this privacy policy. In this context, Adon Health reserves the right to verify your identity using an appropriate procedure.

15. Definitions

For clarity, this privacy policy uses certain terms in the sense assigned to them by the GDPR. The following definitions serve for clarification and consistent interpretation. Should any of the terms be unclear, you can contact Adon Health and/or the data protection officer at any time.

  • According to Article 4 No. 7 of the GDPR, the "controller" is the person who decides on the purposes and means of processing personal data. In particular, they determine what data is processed, how it is processed, and for what purpose. They are responsible for the processing and must ensure compliance with data protection regulations.
  • According to Article 4 No. 8 GDPR , a “processor” is someone who acts on behalf of the controller and processes personal data on the controller’s behalf.
  • According to Article 4 No. 1 GDPR , “personal data” means any information relating to an identified or identifiable natural person (“data subject”).
  • According to Article 4 No. 2 GDPR, "processing" means all possible types of data processing. This includes, in particular, the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of personal data.
  • According to Article 4 No. 1 GDPR, a “data subject” is any natural person to whom the data processed by the controller can be attributed directly or indirectly.
  • According to Article 4 No. 9 GDPR, the ‘recipient’ is the person to whom personal data are disclosed, regardless of whether that person is a third party or not.
  • According to Article 4 No. 10 GDPR , a ‘third party’ is any person other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
  • According to Article 9(1) of the GDPR , "special categories of personal data" include, in particular, the health data of the data subject. This data requires a higher level of protection.
  • According to Article 4 No. 15 GDPR , “health data” means personal data relating to the physical or mental health of the data subject and from which information about the health status of the data subject can be derived.
  • According to Article 4 No. 11 GDPR, “consent” means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action (e.g. ticking a box provided for this purpose), signifies agreement to the processing of his or her personal data.
  • According to Article 4(5) of the GDPR, “pseudonymization” means that personal data is processed in such a way that it can no longer be attributed to a specific person without additional information. This additional information must be kept separately, and measures must be taken to ensure that the data can no longer be attributed to an identified or identifiable person.
  • According to DIN EN ISO 25237 , “anonymization” describes the process by which personal data is irreversibly altered, either by the controller alone or in cooperation with another party, in such a way that the data subject can no longer be identified, either directly or indirectly.

16. Update of this privacy policy

Adon Health reserves the right to update this privacy policy with future effect in order to respond appropriately to changes in legislation, case law, or economic circumstances. Your rights as a data subject under the GDPR will never be restricted by any changes to this privacy policy.