Privacy Policy
Data Protection Officer
Anosch Aziz-Koch
Email: datenschutz@nosc.ai
If you have any questions regarding data protection, you can contact our Data Protection Officer directly at any time.
Content Delivery Network and DNS (Cloudflare)
We use the Cloudflare service provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, as a Content Delivery Network (CDN) and for DNS resolution as well as DDoS protection.
When you access our website, your requests are routed through the global Cloudflare network. During this process, the following data is processed:
IP address
Accessed URL
HTTP headers (including User-Agent, Referrer)
Timestamp of access
The processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR (legitimate interest in the security and availability of our website).
Cloudflare is certified under the EU-US Data Privacy Framework (DPF). In addition, we have concluded Standard Contractual Clauses (SCCs). Cloudflare also has Binding Corporate Rules (BCRs).
Further information: https://www.cloudflare.com/privacypolicy/
Error Monitoring (Sentry)
To detect and resolve technical errors, we use Sentry provided by Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
In the event of an error, the following data is processed:
Pseudonymized usage data (e.g., browser type, operating system)
IP address (truncated)
Error messages and stack traces
Timestamp of the error
The processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR (legitimate interest in the stability and error-free operation of our software).
Sentry is certified under the EU-US Data Privacy Framework (DPF). In addition, we have concluded Standard Contractual Clauses (SCCs). Data processing primarily takes place on servers in the EU/Germany; in the case of support inquiries, a transfer to the USA may occur.
Further information: https://sentry.io/privacy/
HubSpot – Third-Country Transfer
HubSpot, Inc. is based in the USA (25 First Street, 2nd Floor, Cambridge, MA 02141). HubSpot is certified under the EU-US Data Privacy Framework (DPF) (certification can be verified at https://www.dataprivacyframework.gov/). In addition, we have concluded Standard Contractual Clauses (SCCs).
Subprocessors
Framer B.V.
Purpose: Website hosting and content management system
Registered office: Keizersgracht 126, 1015CW Amsterdam, Netherlands
Processed data: IP addresses, HTTP metadata, access times, page views
Data location: EU (Netherlands/Germany)
Third-country transfer: No (processing within the EU/EEA)
Guarantees: Data Processing Agreement (DPA) concluded
Further information: https://www.framer.com/privacy/
HubSpot, Inc.
Purpose: CRM, contact management, forms, and email marketing if applicable
Registered office: 25 First Street, 2nd Floor, Cambridge, MA 02141, USA
Processed data: Name, email address, phone number, company data, form entries, communication history
Data location: Primarily EU (Frankfurt), USA if applicable for support inquiries
Third-country transfer: Possible (USA)
Guarantees: Certified under the EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (SCCs), Data Processing Agreement (DPA)
Further information: https://legal.hubspot.com/privacy-policy
Meta Platforms Ireland Ltd.
Purpose: Website analytics and conversion tracking (Meta Pixel)
Registered office: Merrion Road, Dublin 4, D04 X2K5, Ireland (Parent company: Meta Platforms, Inc., Menlo Park, CA, USA)
Processed data: IP address, page views, interactions, cookie data, device information
Data location: EU/USA
Third-country transfer: Possible (USA)
Guarantees: Certified under the EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (SCCs)
Further information: https://www.facebook.com/privacy/policy/
Storage Periods
Google Analytics 4: The data is automatically deleted after the configured retention period expires. We have set a retention period of 14 months.
Meta Pixel: The Meta Pixel cookie (_fbp) has a lifespan of 90 days. Conversion data is deleted after a maximum of 180 days.
HubSpot: Contact data is stored for the duration of the business relationship and deleted within 12 months after termination, provided there are no statutory retention obligations to the contrary. Form data is stored for 12 months.
Sentry: Error logs are automatically deleted after 90 days.
Cloudflare: Access logs are stored for a maximum of 72 hours and then deleted.
Contact Form: Inquiries via the contact form are retained for the duration of processing and subsequently for 6 months, unless an ongoing business contact arises.
Automated Decision-Making
Automated decision-making within the meaning of Art. 22 GDPR, which produces legal effects concerning you or similarly significantly affects you, does not take place.
Our AI-powered features (e.g., AI medical receptionist, AI medical referral/discharge letter generation) are intended solely for medical practice support and documentation. All AI-generated results are reviewed and approved by the attending physician before being entered into the patient's record. The final decision always rests with the medical professional.
Made in Germany